Spiffyplugins maintains a focused portfolio of WordPress plugins, notably Spiffy Calendar and WP Flow Plus, that provide calendaring and workflow functionality to website administrators. The vendor's vulnerability profile recurs through web-application input-handling and access-control weakness classes, including cross-site scripting, SQL injection, CSRF, and authorization-bypass flaws that are characteristic of plugin-based extensibility. A meaningful share of its disclosures reach serious severity; current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spiffyplugins over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46859CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows SQL Injection.This issue | Nov 3, 2023 | 9.8 | 26 | NO | NO |
CVE-2025-68523HIGH Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spi | Dec 24, 2025 | 8.1 | 25 | NO | NO |
CVE-2024-38692HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy | Jul 22, 2024 | 7.2 | 22 | NO | NO |
CVE-2025-58625MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allows Stored XSS.This issue affects | Sep 3, 2025 | 5.9 | 21 | NO | NO |
CVE-2024-43969HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy | Sep 17, 2024 | 7.6 | 21 | NO | NO |
CVE-2022-29434MEDIUM Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events. | May 20, 2022 | 5.4 | 20 | NO | NO |
CVE-2024-45458MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Reflected XSS.This issue | Sep 15, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-32122MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spiffy Plugins Spiffy Calendar plugin <= 4.9.3 versions. | Aug 18, 2023 | 6.1 | 19 | NO | NO |
CVE-2024-30528MEDIUM Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10. | Jun 4, 2024 | 6.3 | 18 | NO | NO |
CVE-2024-30427MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy | Mar 29, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spiffyplugins.
Media articles that mention a CVE ID that affects a product developed by Spiffyplugins — matched by CVE ID, not by vendor name.