Siteground is a web hosting provider whose vulnerability footprint centers on its security and performance optimization products, with the observed exposure recurrently involving authentication and authorization mechanisms such as missing authentication for critical functions, authentication bypass conditions, and improper or missing authorization controls. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Siteground over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0234HIGH The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue. | Feb 6, 2023 | 8.8 | 35 | NO | NO |
CVE-2022-0993CRITICAL The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity veri | Apr 19, 2022 | 9.8 | 34 | NO | NO |
CVE-2019-25217CRITICAL The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0. | Oct 16, 2024 | 9.8 | 32 | NO | NO |
CVE-2022-0992CRITICAL The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity veri | Apr 19, 2022 | 9.8 | 32 | NO | NO |
CVE-2024-32532MEDIUM Missing Authorization vulnerability in SiteGround Speed Optimizer.This issue affects Speed Optimizer: from n/a through 7.4.6. | Apr 17, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Siteground.
Media articles that mention a CVE ID that affects a product developed by Siteground — matched by CVE ID, not by vendor name.