Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xtendify

First CVE: Oct 25, 2023Active for: 3 yearsTotal CVEs: 12
32.1
VTI Score
Medium

Xtendify develops a modest portfolio of web-based productivity and collaboration applications including WOffice, Simple Calendar, and EOnet Manual User Approve, positioned for small to mid-market deployment. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through authentication and access-control weaknesses—including authentication bypass, improper privilege management, path traversal, and cross-site request forgery—alongside web-tier input-validation issues such as cross-site scripting that are typical of application-layer exposure in this product class. Defenders should prioritize patch deployment for this vendor and audit user-access configurations in affected environments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xtendify over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2023
2 years ago
Most Recent CVE
Aug 2, 2025
356 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-43153CRITICAL
Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10.
Aug 13, 20249.829NONO
CVE-2025-2798CRITICAL
The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during
Apr 4, 20259.828NONO
CVE-2024-43234CRITICAL
Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice woffice allows Authentication Bypass.This issue affects Woffice: from n/a through <= 5.4
Dec 16, 20249.827NONO
CVE-2024-37470CRITICAL
Missing Authorization vulnerability in WofficeIO Woffice Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woffice Core: from n/a through 5.4.
Nov 1, 20249.826NONO
CVE-2025-7694HIGH
The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_delete() function in all version
Aug 2, 20257.525NONO
CVE-2025-2780HIGH
The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'saveFeaturedImage' function in
Apr 4, 20258.825NONO
CVE-2023-46189HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Simple Calendar – Google Calendar Plugin <= 3.2.5 versions.
Oct 25, 20238.824NONO
CVE-2024-37472MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.
Jul 4, 20246.119NONO
CVE-2024-37471MEDIUM
Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.
Jul 4, 20246.119NONO
CVE-2024-8549MEDIUM
The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on th
Sep 25, 20246.118NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
42%
25%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None6 (50.0%)
Unknown0 (0.0%)
Required6 (50.0%)
Privileges Required
Low2 (16.7%)
High1 (8.3%)
None9 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xtendify.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xtendify — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xtendify's Products

View all 2 CNAs →

Top CWEs