Soflyy develops a focused line of WordPress plugins and page-builder tools spanning data import/export functionality and website design capabilities, products that operate within the WordPress ecosystem and handle user-supplied content and configuration data. The vendor's vulnerability exposure recurs through application-layer input-handling weakness classes, including cross-site scripting, code injection, SQL injection, and cross-site request forgery, which are characteristic of web-facing plugins that process untrusted input and manage administrative operations. These weakness classes reflect the attack surface inherent to WordPress extensions that interface with the core publishing platform and user data without adequate input validation or request protection. Defenders tracking WordPress deployments should monitor this vendor's updates and apply patches to affected plugins as part of broader WordPress ecosystem maintenance; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Soflyy over time
Signals from CVEs in this vendor scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57735HIGH Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. | Jul 23, 2026 | 7.1 | 29 | NO | NO |
CVE-2024-31390CRITICAL : Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2. | Apr 3, 2024 | 9.9 | 27 | NO | NO |
CVE-2022-3395HIGH The WP All Export Pro WordPress plugin before 1.7.9 uses the contents of the cc_sql POST parameter directly as a database query, allowing users which has been given permission to r | Oct 25, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-2711HIGH The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as a | Nov 7, 2022 | 7.2 | 25 | NO | NO |
CVE-2024-7419HIGH The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export fields. This is due to the missi | Feb 7, 2025 | 8.8 | 24 | NO | NO |
CVE-2023-5886HIGH The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request life | Dec 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-46841HIGH Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Oxygen Builder plugin <= 4.4 versions. | Oct 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-3418HIGH The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administ | Nov 7, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-3394HIGH The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which ha | Oct 25, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-36386HIGH Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress. | Sep 21, 2022 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (34 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Soflyy.
Media articles that mention a CVE ID that affects a product developed by Soflyy — matched by CVE ID, not by vendor name.