Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Spiffyplugins

First CVE: Feb 21, 2022Active for: 4 yearsTotal CVEs: 16
16.9
VTI Score
Low

Spiffyplugins maintains a focused portfolio of WordPress plugins, notably Spiffy Calendar and WP Flow Plus, that provide calendaring and workflow functionality to website administrators. The vendor's vulnerability profile recurs through web-application input-handling and access-control weakness classes, including cross-site scripting, SQL injection, CSRF, and authorization-bypass flaws that are characteristic of plugin-based extensibility. A meaningful share of its disclosures reach serious severity; current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Spiffyplugins over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 2022
4 years ago
Most Recent CVE
Dec 24, 2025
212 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-46859CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows SQL Injection.This issue
Nov 3, 20239.826NONO
CVE-2025-68523HIGH
Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spi
Dec 24, 20258.125NONO
CVE-2024-38692HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy
Jul 22, 20247.222NONO
CVE-2025-58625MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allows Stored XSS.This issue affects
Sep 3, 20255.921NONO
CVE-2024-43969HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy
Sep 17, 20247.621NONO
CVE-2022-29434MEDIUM
Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.
May 20, 20225.420NONO
CVE-2024-45458MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Reflected XSS.This issue
Sep 15, 20246.119NONO
CVE-2023-32122MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spiffy Plugins Spiffy Calendar plugin <= 4.9.3 versions.
Aug 18, 20236.119NONO
CVE-2024-30528MEDIUM
Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.
Jun 4, 20246.318NONO
CVE-2024-30427MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy
Mar 29, 20246.118NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
75%
19%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (43.8%)
Unknown0 (0.0%)
Required9 (56.3%)
Privileges Required
Low7 (43.8%)
High3 (18.8%)
None6 (37.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Spiffyplugins.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Spiffyplugins — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Spiffyplugins's Products

View all 2 CNAs →

Top CWEs