Simonpedge develops responsive web-content slider and carousel products, with vulnerabilities concentrated in input-handling weaknesses characteristic of client-side web components. The recurring signal centers on cross-site scripting flaws in its Slide Anything line, reflecting the risks inherent in dynamically rendered HTML content. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simonpedge over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2413MEDIUM The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a logged in user with roles | Jan 16, 2024 | 5.4 | 19 | NO | NO |
CVE-2023-28499MEDIUM Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions. | Nov 7, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simonpedge.
Media articles that mention a CVE ID that affects a product developed by Simonpedge — matched by CVE ID, not by vendor name.