Slidervilla's vulnerability footprint centers on a narrowly scoped portfolio of web-based slider and carousel components, including its Testimonial Slider, Smooth Slider, and DBox Slider products. The recurrent signal is rooted in application-layer input handling, with vulnerability disclosures clustering around SQL injection, cross-site scripting, and cross-site request forgery—weakness classes typical of server-side web components that process untrusted data. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Slidervilla over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44741HIGH Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slider plugin <= 1.3.1 on WordPress. | Nov 8, 2022 | 8.8 | 27 | NO | NO |
CVE-2018-5374HIGH The Dbox 3D Slider Lite plugin through 1.2.2 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter). | Jan 12, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-5372HIGH The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter). | Jan 12, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-5373HIGH The Smooth Slider plugin through 2.8.6 for WordPress has SQL Injection via smooth-slider.php (trid parameter). | Jan 12, 2018 | 8.8 | 25 | NO | NO |
CVE-2015-9454HIGH The smooth-slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin current_slider_id parameter. | Oct 7, 2019 | 8.8 | 22 | NO | NO |
CVE-2015-9417MEDIUM The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS. | Sep 26, 2019 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Slidervilla.
Media articles that mention a CVE ID that affects a product developed by Slidervilla — matched by CVE ID, not by vendor name.