Zeen101 develops the Leaky Paywall plugin, a content-access and subscription-management system for web publishers that depends on proper input handling at the client and server interface. The observed vulnerability pattern centers on cross-site scripting flaws arising from improper neutralization of user input during web page generation, a class of weakness endemic to web applications that process and reflect user-supplied data. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zeen101 over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66124MEDIUM Missing Authorization vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leaky Paywall: | Dec 16, 2025 | 5.3 | 19 | NO | NO |
CVE-2021-39357MEDIUM The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the ~/class.php file which allowed attacke | Oct 21, 2021 | 4.8 | 19 | NO | NO |
CVE-2025-31083MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Stored XSS.This issue affects Leaky | Mar 28, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-37540MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Cross Site Request Forgery.This issue affects Leaky Paywall: from n/a through <= 4.21. | Jan 2, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zeen101.
Media articles that mention a CVE ID that affects a product developed by Zeen101 — matched by CVE ID, not by vendor name.