Zixn's vulnerability footprint is concentrated in a small set of web-based products and plugins, including e-commerce extensions and content management integrations, that handle user authentication and form submission. The recurring vulnerability patterns center on access-control and input-handling issues—missing authorization checks, cross-site request forgery, and cross-site scripting—which are characteristic of web application layers where authentication and output encoding are critical. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zixn over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46775HIGH Cross-Site Request Forgery (CSRF) vulnerability in Djo Original texts Yandex WebMaster plugin <= 1.18 versions. | Nov 6, 2023 | 8.8 | 25 | NO | NO |
CVE-2024-24932MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Djo VK Poster Group allows Reflected XSS.This issue affects VK Poster Group: f | Feb 12, 2024 | 6.1 | 21 | NO | NO |
CVE-2024-10854MEDIUM The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buy_one_click_import_options AJAX act | Nov 13, 2024 | 4.3 | 17 | NO | NO |
CVE-2024-10853MEDIUM The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the removeorder AJAX action in all versio | Nov 13, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zixn.
Media articles that mention a CVE ID that affects a product developed by Zixn — matched by CVE ID, not by vendor name.