Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Solwininfotech

First CVE: Jan 30, 2023Active for: 3 yearsTotal CVEs: 12
34.6
VTI Score
Medium

Solwinfotech develops a portfolio of WordPress plugins and web-application extensions, a niche product category with a recurring pattern of web-tier input-handling flaws. Its vulnerabilities skew toward serious outcomes and concentrate in weakness classes including cross-site scripting, SQL injection, CSV formula injection, and authorization bypass—the durable signature of inadequate input validation and access control in plugin codebases. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Solwininfotech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2023
3 years ago
Most Recent CVE
Jan 7, 2026
198 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-37966CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log user-activity-log allows SQL Injection.This
Oct 31, 20239.828NONO
CVE-2023-3435CRITICAL
The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature,
Aug 14, 20239.827NONO
CVE-2025-11877HIGH
The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_login_failed' lacks a capabilit
Jan 7, 20267.526NONO
CVE-2023-4279HIGH
This User Activity Log WordPress plugin before 1.6.7 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be use
Sep 4, 20237.523NONO
CVE-2023-5133HIGH
This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be
Oct 16, 20237.522NONO
CVE-2024-31356HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log.This issue affects User Activity Log: from n
Apr 10, 20247.621NONO
CVE-2022-45078HIGH
Improper Neutralization of Formula Elements in a CSV File vulnerability in Solwin Infotech User Blocker.This issue affects User Blocker: from n/a through 1.5.5.
Nov 7, 20237.221NONO
CVE-2023-2761HIGH
The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading
Jul 24, 20237.220NONO
CVE-2023-30485MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Solwin Infotech Responsive WordPress Slider – Avartan Slider Lite plugin <= 1.5.3 versions.
Sep 4, 20236.119NONO
CVE-2023-5167MEDIUM
The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Store
Oct 16, 20235.416NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
33%
50%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (75.0%)
Unknown0 (0.0%)
Required3 (25.0%)
Privileges Required
Low3 (25.0%)
High3 (25.0%)
None6 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Solwininfotech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Solwininfotech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Solwininfotech's Products

View all 3 CNAs →

Top CWEs