Templatesnext develops web design and templating tools, including its Toolkit and OnePagerbrand products, with a niche vulnerability footprint centered on application-level input-handling concerns. The durable signal reflects cross-site scripting weaknesses characteristic of web-facing generation and editing interfaces; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Templatesnext over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22712MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TemplatesNext TemplatesNext ToolKit plugin <= 3.2.7 versions. | Mar 23, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-0333MEDIUM The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using them to generate an HTML tag, which could allow users with t | Feb 13, 2023 | 5.4 | 19 | NO | NO |
CVE-2022-4678MEDIUM The TemplatesNext ToolKit WordPress plugin before 3.2.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode | Feb 13, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-35753MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TemplatesNext TemplatesNext OnePager allows Stored XSS.This issue affec | Jun 8, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Templatesnext.
Media articles that mention a CVE ID that affects a product developed by Templatesnext — matched by CVE ID, not by vendor name.