Tooltipy Project maintains a focused JavaScript tooltip utility library where the observed vulnerability signal centers on cross-site scripting conditions arising from improper input neutralization during web page generation. This modestly scoped exposure reflects the library's role in dynamically rendering tooltip content in the browser context; current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tooltipy Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000505MEDIUM Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybody to duplicate posts. This atta | Jun 26, 2018 | 6.5 | 20 | NO | NO |
CVE-2018-1000512MEDIUM Tooltipy Tooltipy (tooltips for WP) version 5 contains a Cross Site Scripting (XSS) vulnerability in Glossary shortcode that can result in could allow anybody to do almost anything | Jun 26, 2018 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tooltipy Project.
Media articles that mention a CVE ID that affects a product developed by Tooltipy Project — matched by CVE ID, not by vendor name.