Syntacticsinc maintains the eAsync product, a web-based synchronization and collaboration tool whose vulnerability exposure centers on web-application input handling and access control, with a durable signal across cross-site scripting, cross-site request forgery, authorization bypass, and unrestricted file upload. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Syntacticsinc over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1952CRITICAL The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and sub | Jul 11, 2022 | 9.8 | 55 | NO | YES |
CVE-2024-9450MEDIUM The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow atta | May 15, 2025 | 6.5 | 18 | NO | NO |
CVE-2023-38384MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Syntactics, Inc. EaSYNC plugin <= 1.3.7 versions. | Aug 8, 2023 | 6.1 | 18 | NO | NO |
CVE-2025-4691MEDIUM The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i | May 31, 2025 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Syntacticsinc.
Media articles that mention a CVE ID that affects a product developed by Syntacticsinc — matched by CVE ID, not by vendor name.