Sirv operates an image optimization, resizing, and content-delivery platform that serves as a backend component for e-commerce and media-rich web properties. Its vulnerability surface centers on access-control and input-handling weaknesses—including missing authorization checks, authorization-bypass conditions tied to user-controlled parameters, privilege-assignment errors, and injection flaws such as SQL injection and cross-site scripting—that are characteristic of web-facing platforms handling sensitive image metadata and user sessions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sirv over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10950HIGH The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter. | Sep 13, 2019 | 8.8 | 28 | NO | NO |
CVE-2024-8480HIGH The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_si | Sep 6, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-5853HIGH The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_file_by_chanks AJAX | Jun 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-50898HIGH Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2. | Mar 15, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-10855HIGH The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validat | Nov 20, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-27950HIGH Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0. | Mar 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-32959HIGH Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.2. | May 17, 2024 | 8.8 | 22 | NO | NO |
CVE-2022-4119MEDIUM The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perfor | Jan 2, 2023 | 4.8 | 19 | NO | NO |
CVE-2025-46233MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv sirv allows Stored XSS.This issue affects Sirv | Apr 22, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-8964MEDIUM The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.2.9 due t | Oct 8, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sirv.
Media articles that mention a CVE ID that affects a product developed by Sirv — matched by CVE ID, not by vendor name.