Saas.Group maintains the Juicer product, a social media content-management and aggregation platform with a narrowly scoped vulnerability footprint centered on web application input handling. The recurring signal indicates susceptibility to cross-site scripting vulnerabilities, a pattern typical of client-facing web applications where output encoding and input sanitization matter to defense. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Saas.Group over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-53737MEDIUM Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject sc | Jun 10, 2026 | 6.1 | 26 | NO | NO |
CVE-2023-0172MEDIUM The Juicer WordPress plugin before 1.11 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which | Mar 13, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Saas.Group.
Media articles that mention a CVE ID that affects a product developed by Saas.Group — matched by CVE ID, not by vendor name.