Stream
Vendor:
First CVE: Nov 17, 2021 · Active for 4 years
6
Total CVEs
More Total CVEs than 80% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Stream over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2021
4 years ago
Most Recent CVE
Feb 17, 2025
522 days ago
CVE Severity & Scoring
Stream6 CVEs
50%
50%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required2 (33.3%)
Privileges Required
Low3 (50.0%)
High1 (16.7%)
None2 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24772HIGH The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading | Nov 17, 2021 | 8.8 | 27 | NO | NO |
CVE-2024-7423HIGH The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the | Sep 13, 2024 | 8.8 | 25 | NO | NO |
CVE-2022-4384MEDIUM The Stream WordPress plugin before 3.9.2 does not prevent users with little privileges on the site (like subscribers) from using its alert creation functionality, which may enable | Feb 6, 2023 | 6.5 | 23 | NO | NO |
CVE-2022-43490HIGH Cross-Site Request Forgery (CSRF) vulnerability in XWP Stream plugin <= 3.9.2 versions. | May 25, 2023 | 8.8 | 21 | NO | NO |
CVE-2022-43450MEDIUM Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2. | Dec 19, 2023 | 6.5 | 20 | NO | NO |
CVE-2024-13879MEDIUM The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2 due to insufficient validation on the webhook feature. This | Feb 17, 2025 | 5.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Stream
Top CWEs
Versions
No cataloged versions.