Whiletrue's vulnerability footprint centers on a modest widget product that handles user-generated content and database interactions, with the durable signal rooted in application-layer input-handling issues such as cross-site request forgery and SQL injection. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Whiletrue over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-49628HIGH Cross-Site Request Forgery (CSRF) vulnerability in whiletrue Most And Least Read Posts Widget most-and-least-read-posts-widget allows Cross Site Request Forgery.This issue affects | Oct 20, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-52133HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhileTrue Most And Least Read Posts Widget.This issue affects Most And Least R | Dec 31, 2023 | 8.8 | 24 | NO | NO |
CVE-2025-39549MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in whiletrue Most And Least Read Posts Widget most-and-least-read-posts-widget al | Apr 16, 2025 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Whiletrue.
Media articles that mention a CVE ID that affects a product developed by Whiletrue — matched by CVE ID, not by vendor name.