Sedlex maintains a small portfolio of web-based utilities and tools, including quotation systems, traffic management, and image-handling components, that collectively present a modest but focused web-application attack surface. The recurring vulnerability classes center on authorization, CSRF, output encoding, cross-site scripting, and SQL injection—weaknesses characteristic of web application input handling and access-control design. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sedlex over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22735HIGH The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX actions and is lacking escaping of user data when using it | Mar 14, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-22734MEDIUM The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does not sanitise and escape Quotes. As a result, attacker could m | Mar 14, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-42460MEDIUM Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress. | Nov 10, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-41695MEDIUM Missing Authorization vulnerability in SedLex Traffic Manager.This issue affects Traffic Manager: from n/a through 1.4.5. | Jan 17, 2024 | 6.5 | 18 | NO | NO |
CVE-2022-41619MEDIUM Missing Authorization vulnerability in SedLex Image Zoom.This issue affects Image Zoom: from n/a through 1.8.8. | Jan 17, 2024 | 6.5 | 18 | NO | NO |
CVE-2022-40219MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in SedLex FavIcon Switcher plugin <= 1.2.11 at WordPress allows plugin settings change. | Sep 21, 2022 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sedlex.
Media articles that mention a CVE ID that affects a product developed by Sedlex — matched by CVE ID, not by vendor name.