Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Smashballoon

First CVE: Sep 13, 2021Active for: 5 yearsTotal CVEs: 14
18.8
VTI Score
Low

Smashballoon develops a suite of WordPress plugins for embedding and displaying social media feeds and reviews, with a recurring vulnerability profile concentrated in its Custom Twitter Feeds, Social Post Feed, Feeds for YouTube, and Reviews Feed products. The durable signal across these plugins centers on web-application input-handling and authorization weaknesses—cross-site request forgery, cross-site scripting, command injection, and missing authorization controls—typical of server-side plugins that process and render user-supplied and external content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Smashballoon over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 13, 2021
4 years ago
Most Recent CVE
Oct 31, 2024
632 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-25065MEDIUM
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
Jan 17, 20225.430NOYES
CVE-2022-33974HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions.
May 29, 20238.825NONO
CVE-2024-49685HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Forgery.This issue affects Custom
Oct 31, 20248.824NONO
CVE-2023-52136HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Twitter Feeds – A Tweets Widget o
Jan 5, 20248.824NONO
CVE-2021-24508MEDIUM
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authentic
Sep 13, 20216.121NONO
CVE-2022-4477MEDIUM
The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could
Jan 16, 20235.420NONO
CVE-2023-4841MEDIUM
The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in versions up to, and including, 2.1 due to insufficient input
Sep 14, 20235.419NONO
CVE-2021-24918MEDIUM
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user
Nov 29, 20215.419NONO
CVE-2024-8200MEDIUM
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve
Aug 27, 20244.317NONO
CVE-2024-6256MEDIUM
The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in al
Jul 11, 20245.417NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
79%
21%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (7.1%)
Unknown0 (0.0%)
Required13 (92.9%)
Privileges Required
Low6 (42.9%)
High1 (7.1%)
None7 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Smashballoon.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Smashballoon — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Smashballoon's Products

View all 3 CNAs →

Top CWEs