Smash balloon social photo feed – easy social feeds plugin
This hub aggregates every CVE we track for Smash balloon social photo feed – easy social feeds plugin, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM3
Monthly trend
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
1
1
2024-092026-08
Latest CVEs
The 3 most recently published vulnerabilities affecting Smash balloon social photo feed – easy social feeds plugin.
- CVE-2026-15452Smash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting via REQUEST_URI Query String4.7
- CVE-2026-12002Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter4.7
- CVE-2025-4583Smash Balloon Instagram Feed <= 6.9.0 (Free) & <= 6.8.0 (Pro) - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-plugin` Attribute5.4
Product normalization is registry-driven with AI assist and human review. How it works