Rockcontent's vulnerability footprint centers on its Rock Convert web-based content and conversion platform, with the observed exposure characterized by cross-site scripting weaknesses stemming from improper input neutralization in web page generation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rockcontent over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62911MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Content Rock Convert rock-convert allows Stored XSS.This issue affects Ro | Oct 27, 2025 | 6.5 | 20 | NO | NO |
CVE-2022-36428MEDIUM Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress. | Nov 3, 2022 | 4.8 | 19 | NO | NO |
CVE-2022-3441MEDIUM The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site | Oct 31, 2022 | 4.8 | 18 | NO | NO |
CVE-2022-3440MEDIUM The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading t | Oct 31, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rockcontent.
Media articles that mention a CVE ID that affects a product developed by Rockcontent — matched by CVE ID, not by vendor name.