Favorites
This hub aggregates every CVE we track for Favorites, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM4HIGH2LOW1
Monthly trend
0
0
0
0
0
1
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 7 most recently published vulnerabilities affecting Favorites.
- CVE-2025-60202WordPress Favorites plugin <= 2.3.6 - Local File Inclusion vulnerability7.5
- CVE-2025-1452Favorites < 2.3.5 - Admin+ Stored XSS3.5
- CVE-2024-2948Favorites <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode7.2
- CVE-2023-2304Favorites <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode6.4
- CVE-2021-26024The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.5.3
- CVE-2021-26023The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.6.1
- CVE-2015-9513The Easy Digital Downloads (EDD) Favorites extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x ...6.1
Product normalization is registry-driven with AI assist and human review. How it works