Smub
34 CVEs tracked since 2024. Since Jul 2024, none of them reached CISA KEV.
Smub CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2024-07 | 6 | 0 |
| 2024-08 | 4 | 0 |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | 4 | 0 |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | 5 | 0 |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | 6 | 0 |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | null or fewer | |
| 2026-05 | 9 | 0 |
Products
The products that kept showing up in Smub's monthly top three, with their CVEs summed over those months.
- Easy Digital Downloads – Ecommerce Payments and Subscriptions Made Easy5
- Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More3
- All In One Seo – Powerful Seo Plugin To Boost Seo Rankings & Increase Traffic2
- Photo Gallery, Sliders, Proofing and Themes – Nextgen Gallery2
- Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, Tripadvisor, and More2
- Athemes Addons For Elementor1
- Athemes Starter Sites1
- Charitable – Donation Plugin For WordPress – Fundraising With Recurring Donations & More1
- Custom Twitter Feeds – A Tweets Widget Or X Feed Widget1
- Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More1
Latest CVEs
The 15 most recently published vulnerabilities affecting Smub.
- CVE-2026-88996WPForms <= 2.0.2 - Reflected Cross-Site Scripting via 'page_title' POST Parameter6.1
- CVE-2026-84909Custom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute6.4
- CVE-2026-77189Charitable <= 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'order' Shortcode Attribute6.5
- CVE-2026-3423Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description6.4
- CVE-2026-16775Smash Balloon Social Post Feed <= 4.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute6.4
- CVE-2026-15452Smash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting via REQUEST_URI Query String4.7
- CVE-2026-12476Easy Digital Downloads <= 3.6.9 - Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter7.2
- CVE-2026-15782WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content4.9
- CVE-2026-12002Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter4.7
- CVE-2026-12127WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name5.3
- CVE-2026-8613aThemes Addons for Elementor <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Widget Setting6.4
- CVE-2026-7792WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint5.3
- CVE-2026-10038Charitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter4.3
- CVE-2026-7526PDF Embedder <= 4.9.3 - Authenticated (Contributor+) Information Exposure via Block Editor Page4.3
- CVE-2026-7533Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parameter4.3
The record
- Peak rank
- #125 in Jul 2024
- Busiest month shown
- May 2026, 9 CVEs
- Months with a KEV entry
- 0 since Jul 2024
- Monthly snapshots
- 6 since 2024