Zingiri's vulnerability footprint centers on a compact set of web-facing products including its e-commerce platform, forum software, and theme customization plugin, where the durable signal reflects common application-layer weaknesses such as code injection, path traversal, and cross-site scripting. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zingiri over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4033HIGH Multiple unspecified vulnerabilities in the Zingiri Web Shop plugin before 2.4.0 for WordPress have unknown impact and attack vectors. | Jul 18, 2012 | 10.0 | 28 | NO | NO |
CVE-2012-6506MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) pag | Jan 24, 2013 | 4.3 | 25 | NO | YES |
CVE-2012-0934HIGH PHP remote file inclusion vulnerability in ajax/savetag.php in the Theme Tuner plugin for WordPress before 0.8 allows remote attackers to execute arbitrary PHP code via a URL in th | Jan 29, 2012 | 7.5 | 25 | NO | NO |
CVE-2012-4920MEDIUM Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugin before 1.4.4 for WordPress allows remote attackers to read | Apr 4, 2014 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zingiri.
Media articles that mention a CVE ID that affects a product developed by Zingiri — matched by CVE ID, not by vendor name.