Zemanta develops a narrow set of content-recommendation and search plugins that integrate with publishing platforms, with a durable vulnerability signal centered on application-layer input-handling weaknesses including cross-site request forgery and SQL injection. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zemanta over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2316HIGH SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the s para | Mar 9, 2014 | 7.5 | 20 | NO | NO |
CVE-2013-3476MEDIUM Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.6.2 for WordPress allows remote attackers to hijack the authentication of users for r | Jun 2, 2014 | 6.8 | 18 | NO | NO |
CVE-2013-3257MEDIUM Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote attackers to hijack the authentication of users for requests th | Jun 2, 2014 | 6.8 | 18 | NO | NO |
CVE-2013-3477MEDIUM Cross-site request forgery (CSRF) vulnerability in the Related Posts by Zemanta plugin before 1.3.2 for WordPress allows remote attackers to hijack the authentication of unspecifie | May 27, 2014 | 6.8 | 18 | NO | NO |
CVE-2014-3843MEDIUM Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the authentication of unspecified victi | May 22, 2014 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zemanta.
Media articles that mention a CVE ID that affects a product developed by Zemanta — matched by CVE ID, not by vendor name.