CVE Tools

Saadiqbal

4 CVEs tracked since 2024. Since Sep 2024, none of them reached CISA KEV.

Saadiqbal CVEs per month

Sep 2024 to Sep 2024. Point at a month, or focus the strip and use the arrow keys.
Saadiqbal CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0940

Products

The products that kept showing up in Saadiqbal's monthly top three, with their CVEs summed over those months.

  1. Advanced File Manager – Ultimate File Manager For WordPress and Document Library Solution31 month
  2. Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – Mycred11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Saadiqbal.

  1. CVE-2026-12739WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion4.3
  2. CVE-2026-17149myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute6.4
  3. CVE-2026-15009Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter6.1
  4. CVE-2026-6627WPFormify <= 1.1.1 - Missing Authorization8.2
  5. CVE-2026-11995Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action()5.3
  6. CVE-2026-12144Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escalation via 'user_role_set' Parameter8.8
  7. CVE-2026-12738WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action4.3
  8. CVE-2026-12097User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Settings Modification5.3
  9. CVE-2026-8607myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode Attribute6.4
  10. CVE-2026-7430Post Snippets <= 4.0.19 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import4.4
  11. CVE-2024-13362Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter6.1
  12. CVE-2026-3090Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type'7.2
  13. CVE-2026-2559Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite5.3
  14. CVE-2026-1674Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema()6.5
  15. CVE-2026-0550myCred <= 2.9.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mycred_load_coupon' Shortcode6.4

The record

Peak rank
#167 in Sep 2024
Busiest month shown
Sep 2024, 4 CVEs
Months with a KEV entry
0 since Sep 2024
Monthly snapshots
1 since 2024
Saadiqbal's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store