Smartlogix develops a WordPress plugin product focused on content insertion and management, with its observed vulnerability exposure centered on web application input-handling and file-upload controls. The recurring weakness classes—cross-site scripting and unrestricted file uploads—reflect common risks in plugin-based WordPress extensibility where sanitization and type validation are critical to preventing both client-side injection and malicious payload execution.
The number and severity of CVEs published that impact products developed by Smartlogix over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17573CRITICAL The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fckeditor/editor/filemanager/brows | Sep 28, 2018 | 9.8 | 30 | NO | NO |
CVE-2023-25461MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in namithjawahar Wp-Insert plugin <= 2.5.0 versions. | Apr 25, 2023 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartlogix.
Media articles that mention a CVE ID that affects a product developed by Smartlogix — matched by CVE ID, not by vendor name.