Favorites
7 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Favorites, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Favorites CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 7 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High2
- Medium4
- Low1
Latest CVEs
The 7 most recently published vulnerabilities affecting Favorites.
- CVE-2025-60202WordPress Favorites plugin <= 2.3.6 - Local File Inclusion vulnerability7.5
- CVE-2025-1452Favorites < 2.3.5 - Admin+ Stored XSS3.5
- CVE-2024-2948Favorites <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode7.2
- CVE-2023-2304Favorites <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode6.4
- CVE-2021-26024The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.5.3
- CVE-2021-26023The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.6.1
- CVE-2015-9513The Easy Digital Downloads (EDD) Favorites extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x ...6.1
Product grouping is registry-driven, with AI assist and human review. How it works