Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Soflyy

First CVE: Mar 9, 2018Active for: 8 yearsTotal CVEs: 34
31.5
VTI Score
Medium

Soflyy develops a focused line of WordPress plugins and page-builder tools spanning data import/export functionality and website design capabilities, products that operate within the WordPress ecosystem and handle user-supplied content and configuration data. The vendor's vulnerability exposure recurs through application-layer input-handling weakness classes, including cross-site scripting, code injection, SQL injection, and cross-site request forgery, which are characteristic of web-facing plugins that process untrusted input and manage administrative operations. These weakness classes reflect the attack surface inherent to WordPress extensions that interface with the core publishing platform and user data without adequate input validation or request protection. Defenders tracking WordPress deployments should monitor this vendor's updates and apply patches to affected plugins as part of broader WordPress ecosystem maintenance; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
34
Total CVEs
More Total CVEs than 98% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Soflyy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 9, 2018
8 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-57735HIGH
Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.
Jul 23, 20267.129NONO
CVE-2024-31390CRITICAL
: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.
Apr 3, 20249.927NONO
CVE-2022-3395HIGH
The WP All Export Pro WordPress plugin before 1.7.9 uses the contents of the cc_sql POST parameter directly as a database query, allowing users which has been given permission to r
Oct 25, 20228.827NONO
CVE-2022-2711HIGH
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as a
Nov 7, 20227.225NONO
CVE-2024-7419HIGH
The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export fields. This is due to the missi
Feb 7, 20258.824NONO
CVE-2023-5886HIGH
The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request life
Dec 18, 20238.824NONO
CVE-2022-46841HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Oxygen Builder plugin <= 4.4 versions.
Oct 3, 20238.824NONO
CVE-2022-3418HIGH
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administ
Nov 7, 20227.224NONO
CVE-2022-3394HIGH
The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which ha
Oct 25, 20227.224NONO
CVE-2022-36386HIGH
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
Sep 21, 20227.224NONO
View all 34 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products34 CVEs
44%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network34 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (44.1%)
Unknown0 (0.0%)
Required19 (55.9%)
Privileges Required
Low5 (14.7%)
High11 (32.4%)
None18 (52.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (34 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Soflyy.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Soflyy — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Soflyy's Products

View all 5 CNAs →

Top CWEs