Thirtybees is a lean e-commerce platform and associated blogging tool focused on small and medium-sized online retailers, with its vulnerability exposure centered on web application input-handling issues such as cross-site scripting. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thirtybees over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45958MEDIUM Thirty Bees Core v1.4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the backup_pagination parameter at /controller/AdminController.php. This | Oct 18, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-52264MEDIUM The beesblog (aka Bees Blog) component before 1.6.2 for thirty bees allows Reflected XSS because controllers/front/post.php sharing_url is mishandled. | Dec 30, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-45957MEDIUM A stored cross-site scripting (XSS) vulnerability in the component admin/AdminRequestSqlController.php of thirty bees before 1.5.0 allows attackers to execute arbitrary web script | Dec 22, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thirtybees.
Media articles that mention a CVE ID that affects a product developed by Thirtybees — matched by CVE ID, not by vendor name.