Visualizer
Vendor:
First CVE: Sep 30, 2019 · Active for 6 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Visualizer over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2019
6 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
CVE Severity & Scoring
Visualizer9 CVEs
56%
33%
11%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (44.4%)
Unknown0 (0.0%)
Required5 (55.6%)
Privileges Required
Low6 (66.7%)
High0 (0.0%)
None3 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16932CRITICAL A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data. | Sep 30, 2019 | 10.0 | 63 | NO | YES |
CVE-2026-65526HIGH Contributor SQL Injection in Visualizer <= 4.0.6 versions. | Jul 23, 2026 | 8.5 | 32 | NO | NO |
CVE-2019-16931MEDIUM A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user ed | Oct 3, 2019 | 6.1 | 32 | NO | YES |
CVE-2022-2444HIGH The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data' parameter in versions up to, | Jul 18, 2022 | 8.8 | 29 | NO | NO |
CVE-2024-35736HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer.This issue affects Visualizer: from n/a through 3.11.1. | Jun 8, 2024 | 8.8 | 26 | NO | NO |
CVE-2026-24573MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS.
This issue affects Visualizer: from n | May 20, 2026 | 6.5 | 25 | NO | NO |
CVE-2022-46848MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager for WordPress plugin <= 3.9.1 versions. | Mar 28, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-27958MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Reflected XSS.This issue affects Visualizer: from | Mar 17, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-23708MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager for WordPress plugin <= 3.9.4 versions. | May 3, 2023 | 5.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
22.2% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Visualizer
Top CWEs
Versions
No cataloged versions.