Solwinfotech develops a portfolio of WordPress plugins and web-application extensions, a niche product category with a recurring pattern of web-tier input-handling flaws. Its vulnerabilities skew toward serious outcomes and concentrate in weakness classes including cross-site scripting, SQL injection, CSV formula injection, and authorization bypass—the durable signature of inadequate input validation and access control in plugin codebases. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Solwininfotech over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37966CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log user-activity-log allows SQL Injection.This | Oct 31, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-3435CRITICAL The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, | Aug 14, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-11877HIGH The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_login_failed' lacks a capabilit | Jan 7, 2026 | 7.5 | 26 | NO | NO |
CVE-2023-4279HIGH This User Activity Log WordPress plugin before 1.6.7 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be use | Sep 4, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-5133HIGH This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be | Oct 16, 2023 | 7.5 | 22 | NO | NO |
CVE-2024-31356HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log.This issue affects User Activity Log: from n | Apr 10, 2024 | 7.6 | 21 | NO | NO |
CVE-2022-45078HIGH Improper Neutralization of Formula Elements in a CSV File vulnerability in Solwin Infotech User Blocker.This issue affects User Blocker: from n/a through 1.5.5. | Nov 7, 2023 | 7.2 | 21 | NO | NO |
CVE-2023-2761HIGH The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading | Jul 24, 2023 | 7.2 | 20 | NO | NO |
CVE-2023-30485MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Solwin Infotech Responsive WordPress Slider – Avartan Slider Lite plugin <= 1.5.3 versions. | Sep 4, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-5167MEDIUM The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Store | Oct 16, 2023 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Solwininfotech.
Media articles that mention a CVE ID that affects a product developed by Solwininfotech — matched by CVE ID, not by vendor name.