Tooltipy is a modestly scoped web application with a narrow product footprint centered on a single product line. The durable signal reflects its web-application context, with the observed vulnerability pattern anchored to cross-site request forgery, a class of session-handling flaw endemic to stateful web interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tooltipy over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000505MEDIUM Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybody to duplicate posts. This atta | Jun 26, 2018 | 6.5 | 20 | NO | NO |
CVE-2018-1000512MEDIUM Tooltipy Tooltipy (tooltips for WP) version 5 contains a Cross Site Scripting (XSS) vulnerability in Glossary shortcode that can result in could allow anybody to do almost anything | Jun 26, 2018 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tooltipy.
Media articles that mention a CVE ID that affects a product developed by Tooltipy — matched by CVE ID, not by vendor name.