Supportflow Project maintains a focused web-based customer support platform where the recurring vulnerability signal centers on cross-site scripting weaknesses in input handling and page generation. Current severity, exploitation status, and exposure metrics are shown in the live-statistics panel alongside this summary.
The number and severity of CVEs published that impact products developed by Supportflow Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10970MEDIUM The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt. | Sep 16, 2019 | 6.1 | 20 | NO | NO |
CVE-2016-10969MEDIUM The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title. | Sep 16, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Supportflow Project.
Media articles that mention a CVE ID that affects a product developed by Supportflow Project — matched by CVE ID, not by vendor name.