Roytanck's vulnerability footprint centers on WordPress plugins, particularly its Cumulus plugin, where the observed exposure reflects application-layer web-input handling issues such as cross-site scripting and improper information disclosure. Current exploitation activity, severity distribution, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Roytanck over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4168MEDIUM Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, | Dec 2, 2009 | 4.3 | 27 | NO | YES |
CVE-2009-4170MEDIUM WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably withou | Dec 2, 2009 | 5.0 | 24 | NO | YES |
CVE-2009-4169MEDIUM Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the WP-Cumulus Plug-in before 1.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via un | Dec 2, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Roytanck.
Media articles that mention a CVE ID that affects a product developed by Roytanck — matched by CVE ID, not by vendor name.