Searchiq's vulnerability profile concentrates in a single search and information-retrieval platform, where the observed weakness classes cluster around web application security issues including cross-site scripting, cross-site request forgery, missing authorization controls, and improper logging of sensitive data. These patterns reflect the input-handling and session-management demands of web-facing query and data-access interfaces. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Searchiq over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0780MEDIUM The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allow | Apr 18, 2022 | 6.1 | 22 | NO | NO |
CVE-2024-31259HIGH Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5. | Apr 10, 2024 | 7.5 | 20 | NO | NO |
CVE-2025-30867MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SearchIQ SearchIQ searchiq allows Stored XSS.This issue affects SearchIQ: from | Mar 27, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-13350MEDIUM The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including | Mar 5, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-10885MEDIUM The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including | Dec 4, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-47832MEDIUM Missing Authorization vulnerability in SearchIQ SearchIQ searchiq allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a thro | Dec 9, 2024 | 5.3 | 16 | NO | NO |
CVE-2024-56229MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in SearchIQ SearchIQ searchiq.This issue affects SearchIQ: from n/a through <= 4.6. | Dec 31, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Searchiq.
Media articles that mention a CVE ID that affects a product developed by Searchiq — matched by CVE ID, not by vendor name.