S Sols develops a narrow product line centered on the Seraphinite Accelerator and related document-source tooling, which despite modest disclosure volume occupies a notable niche position in the vulnerability landscape. The observed vulnerabilities cluster around input-handling and document-processing attack surfaces characteristic of these WordPress and content-management extensions. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by S Sols over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48279HIGH Cross-Site Request Forgery (CSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source allows Cross Site Request Forgery.This issue affects Seraphinite Post .DOCX S | Nov 30, 2023 | 8.8 | 26 | NO | NO |
CVE-2026-3058MEDIUM The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.28.14 via the `seraph_accel_api` AJAX actio | Mar 4, 2026 | 6.5 | 22 | NO | NO |
CVE-2024-38728MEDIUM Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9. | Jul 22, 2024 | 6.4 | 20 | NO | NO |
CVE-2024-1568MEDIUM The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.20.52 via the OnAdminApi_HtmlCheck function. T | Feb 28, 2024 | 6.4 | 19 | NO | NO |
CVE-2023-5610MEDIUM The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect | Nov 20, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-5609MEDIUM The Seraphinite Accelerator WordPress plugin before 2.2.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripti | Nov 20, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-49740MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Seraphinite Solutions Seraphinite Accelerator allows Reflected XSS.This issue | Dec 14, 2023 | 6.1 | 17 | NO | NO |
CVE-2023-5611MEDIUM The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to | Nov 27, 2023 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by S Sols.
Media articles that mention a CVE ID that affects a product developed by S Sols — matched by CVE ID, not by vendor name.