Slimstat Analytics
Vendor:
First CVE: Oct 7, 2018 · Active for 7 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Slimstat Analytics over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2018
7 years ago
Most Recent CVE
Oct 15, 2024
648 days ago
CVE Severity & Scoring
Slimstat Analytics11 CVEs
82%
9%
9%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low4 (36.4%)
High1 (9.1%)
None6 (54.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0630HIGH The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query. | Mar 20, 2023 | 8.8 | 33 | NO | YES |
CVE-2022-45373CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics allows SQL Injection.This issue af | Nov 6, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-4310MEDIUM The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross | Jan 9, 2023 | 6.1 | 21 | NO | NO |
CVE-2019-15112MEDIUM The wp-slimstat plugin before 4.8.1 for WordPress has XSS. | Aug 21, 2019 | 6.1 | 21 | NO | NO |
CVE-2023-4597MEDIUM The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slimstat' shortcode in versions up to, and including, 5.0.9 due to insufficient in | Aug 30, 2023 | 6.4 | 20 | NO | NO |
CVE-2022-45366MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics plugin <= 5.0.4 versions. | May 25, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-9548MEDIUM The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient | Oct 15, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-4598MEDIUM The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 5.0.9 due to insufficient escaping on the us | Oct 20, 2023 | 6.5 | 19 | NO | NO |
CVE-2024-1073MEDIUM The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' parameter in all versions up to, and including, 5.1.3 due to insuffi | Feb 2, 2024 | 5.4 | 18 | NO | NO |
CVE-2015-9273MEDIUM The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via a field associated with JavaScript-based Referer tracking. | Oct 7, 2018 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Slimstat Analytics
Top CWEs
Versions
No cataloged versions.