Scribu develops a front-end editor plugin focused on WordPress and similar content-management platforms, presenting a narrow but directly user-facing attack surface. Disclosed vulnerabilities in this product center on unrestricted file upload handling, a classic input-validation risk in web-facing content tools that can enable unauthorized code execution or data exposure.
The number and severity of CVEs published that impact products developed by Scribu over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-10019CRITICAL The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it | Jul 19, 2025 | 9.8 | 39 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scribu.
Media articles that mention a CVE ID that affects a product developed by Scribu — matched by CVE ID, not by vendor name.