Stevenhenty's vulnerability footprint is narrow, centered on its Drop Shadow Boxes product, with the observed weakness class rooted in cross-site scripting and improper input neutralization during web page generation. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stevenhenty over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23833MEDIUM Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Steven Henty Drop Shadow Boxes plugin <= 1.7.10 versions. | Jul 25, 2023 | 5.4 | 16 | NO | NO |
CVE-2023-5469MEDIUM The Drop Shadow Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dropshadowbox' shortcode in versions up to, and including, 1.7.13 due to insufficient i | Nov 22, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stevenhenty.
Media articles that mention a CVE ID that affects a product developed by Stevenhenty — matched by CVE ID, not by vendor name.