Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tagdiv

First CVE: Sep 16, 2019Active for: 7 yearsTotal CVEs: 29
29.5
VTI Score
Low

Tagdiv is a modestly represented vendor of WordPress themes and plugins—primarily its Composer and Newspaper product lines—that serve as content-management and publishing frameworks for news and media websites. Vulnerabilities affecting the vendor skew toward serious outcomes, frequently acquire public exploit code, and recur through web-application weakness classes including cross-site scripting, cross-site request forgery, PHP remote file inclusion, and improper privilege management that are characteristic of extensible WordPress ecosystem products. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tagdiv over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2019
6 years ago
Most Recent CVE
Jul 13, 2026
11 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-10972CRITICAL
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
Sep 16, 20199.843NOYES
CVE-2022-2627MEDIUM
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting
Oct 31, 20226.132NOYES
CVE-2026-57734HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tag
Jul 13, 20267.131NONO
CVE-2023-3169MEDIUM
The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not valid
Sep 11, 20236.131NOYES
CVE-2024-13645CRITICAL
The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including, 5.3 via module parameter. This makes it possible for unauth
Apr 4, 20259.828NONO
CVE-2017-18634CRITICAL
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
Sep 16, 20199.828NONO
CVE-2023-1597HIGH
The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing una
Jul 10, 20238.826NONO
CVE-2025-50005MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tag
Jan 22, 20266.525NONO
CVE-2025-62031HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer.This issue affects tagDiv Composer: from n/
Nov 6, 20257.124NONO
CVE-2024-3813HIGH
The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' attr
Jun 15, 20248.824NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
72%
17%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network29 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (20.7%)
Unknown0 (0.0%)
Required23 (79.3%)
Privileges Required
Low6 (20.7%)
High3 (10.3%)
None20 (69.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
10.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tagdiv.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tagdiv — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tagdiv's Products

View all 4 CNAs →

Top CWEs