Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wp Slimstat

First CVE: Oct 7, 2018Active for: 8 yearsTotal CVEs: 22

WP Slimstat is a WordPress analytics plugin with a narrowly scoped product portfolio but notable presence in the analytics-plugin segment of WordPress deployments. Its vulnerability disclosures center on the Slimstat Analytics product and reflect input-handling and data-processing patterns typical of web-facing logging and reporting tools. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wp Slimstat over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2018
7 years ago
Most Recent CVE
Oct 15, 2024
647 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-0630HIGH
The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.
Mar 20, 20238.833NOYES
CVE-2022-45373CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics allows SQL Injection.This issue af
Nov 6, 20239.830NONO
CVE-2022-4310MEDIUM
The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross
Jan 9, 20236.121NONO
CVE-2019-15112MEDIUM
The wp-slimstat plugin before 4.8.1 for WordPress has XSS.
Aug 21, 20196.121NONO
CVE-2023-4597MEDIUM
The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slimstat' shortcode in versions up to, and including, 5.0.9 due to insufficient in
Aug 30, 20236.420NONO
CVE-2022-45366MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics plugin <= 5.0.4 versions.
May 25, 20236.120NONO
CVE-2024-9548MEDIUM
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient
Oct 15, 20246.119NONO
CVE-2023-4598MEDIUM
The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 5.0.9 due to insufficient escaping on the us
Oct 20, 20236.519NONO
CVE-2024-1073MEDIUM
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' parameter in all versions up to, and including, 5.1.3 due to insuffi
Feb 2, 20245.418NONO
CVE-2015-9273MEDIUM
The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via a field associated with JavaScript-based Referer tracking.
Oct 7, 20186.118NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
82%
9%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low4 (36.4%)
High1 (9.1%)
None6 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Slimstat.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wp Slimstat — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wp Slimstat's Products

View all 4 CNAs →

Top CWEs