Sermon Browser Project develops a web-based browsing and content-management application where the durable vulnerability signal centers on web-application input-handling and upload controls, including cross-site request forgery, cross-site scripting, and unrestricted file uploads. This represents a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sermon Browser Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0499HIGH The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to mak | Mar 28, 2022 | 8.8 | 29 | NO | NO |
CVE-2016-10897MEDIUM The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues. | Aug 21, 2019 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sermon Browser Project.
Media articles that mention a CVE ID that affects a product developed by Sermon Browser Project — matched by CVE ID, not by vendor name.