Satollo's vulnerability profile concentrates on its Giveaway plugin and related header, footer, and post-injection components, with the durable signal centered on web-application input-handling weaknesses such as code injection and SQL injection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Satollo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24497HIGH The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user to execute arbitrary SQL commands via the $post_id on the op | Aug 23, 2021 | 7.2 | 23 | NO | NO |
CVE-2024-13900HIGH The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated | Feb 21, 2025 | 7.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Satollo.
Media articles that mention a CVE ID that affects a product developed by Satollo — matched by CVE ID, not by vendor name.