Wipeoutmedia develops a CSS and JavaScript toolbox product, a web development utility with a niche deployment footprint. The observed vulnerability signal centers on cross-site scripting flaws arising from improper input neutralization during web page generation, a characteristic exposure pattern for client-side development tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wipeoutmedia over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3703HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wipeoutmedia CSS & JavaScript Toolbox css-javascript-toolbo | Aug 14, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-11928MEDIUM The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 12.0.5 due to insufficient i | Nov 1, 2025 | 4.4 | 19 | NO | NO |
CVE-2023-50823MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wipeout Media CSS & JavaScript Toolbox allows Stored XSS.This issue affects CS | Dec 21, 2023 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wipeoutmedia.
Media articles that mention a CVE ID that affects a product developed by Wipeoutmedia — matched by CVE ID, not by vendor name.