Vasyltech's vulnerability footprint centers on Advanced Access Manager, a narrowly scoped access-control and WordPress plugin product whose disclosures cluster around application-layer input handling and information exposure. The recurring weakness classes—cross-site scripting, path traversal, open redirect, and sensitive information disclosure—reflect the authentication and authorization boundary-crossing risks inherent to access-management middleware, and the vendor's disclosures have an elevated tendency to acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vasyltech over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25213HIGH The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on th | Oct 16, 2024 | 7.5 | 37 | NO | YES |
CVE-2020-35935HIGH The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabl | Jan 1, 2021 | 8.8 | 26 | NO | NO |
CVE-2014-6059HIGH WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability | Jan 13, 2020 | 7.2 | 24 | NO | NO |
CVE-2024-29127MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Reflected XSS.This issue affects Advanced A | Mar 19, 2024 | 6.1 | 18 | NO | NO |
CVE-2021-24830MEDIUM The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting a | Nov 23, 2021 | 4.8 | 18 | NO | NO |
CVE-2023-51674MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Secu | Feb 1, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-51675MEDIUM URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More.This issue affects | Dec 29, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-50881MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Secu | Dec 29, 2023 | 5.4 | 17 | NO | NO |
CVE-2020-35934MEDIUM The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v | Jan 1, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vasyltech.
Media articles that mention a CVE ID that affects a product developed by Vasyltech — matched by CVE ID, not by vendor name.