Vivwebsolutions maintains a focused portfolio centered on its Dynamic Widgets product, with a durable vulnerability pattern concentrated on web-application input-handling and request-validation issues including cross-site scripting, SQL injection, and cross-site request forgery. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vivwebsolutions over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-10100CRITICAL A vulnerability, which was classified as critical, has been found in Dynamic Widgets Plugin up to 1.5.10 on WordPress. This issue affects some unknown processing of the file classe | Apr 10, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-51669HIGH Cross-Site Request Forgery (CSRF) vulnerability in Kalmang Dynamic Widgets dynamic-widgets.This issue affects Dynamic Widgets: from n/a through <= 1.6.4. | Nov 19, 2024 | 8.8 | 25 | NO | NO |
CVE-2015-9437MEDIUM The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter. | Sep 26, 2019 | 6.5 | 17 | NO | NO |
CVE-2015-9436MEDIUM The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix or widget_id parameter. | Sep 26, 2019 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vivwebsolutions.
Media articles that mention a CVE ID that affects a product developed by Vivwebsolutions — matched by CVE ID, not by vendor name.