| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-62737 | WordPress Image Cleanup plugin <= 1.9.2 - Sensitive Data Exposure vulnerability | opicron | Image Cleanup | - | - | 2025-12-09 14:52:22 | Deep Dive |
| CVE-2025-62736 | WordPress Image Cleanup plugin <= 1.9.2 - Broken Access Control vulnerability | opicron | Image Cleanup | - | - | 2025-12-09 14:52:22 | Deep Dive |
| CVE-2025-53272 | WordPress Image Cleanup plugin <= 1.9.2 - Cross Site Request Forgery (CSRF) Vulnerability | opicron | Image Cleanup | Medium | 4.3 | 2025-06-27 13:21:15 | Deep Dive |
| CVE-2024-13962 | Link Following Local Privilege Escalation Vulnerability in Avast Cleanup Premium Version 24.2.16593.17810 | Avast | CleanUp Premium | High | 7.8 | 2025-05-09 15:20:51 | Deep Dive |
| CVE-2024-13961 | Avast Cleanup Premium TuneupSvc Link Following Local Privilege Escalation Vulnerability | Avast | CleanUp Premium | High | 7.8 | 2025-05-09 15:20:42 | Deep Dive |
| CVE-2024-13944 | Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate (Also affects Avast CleanUp and AVG TuneUp) | Norton | Norton Utilities Ultimate | High | 7.8 | 2025-05-09 15:18:34 | Deep Dive |
| CVE-2025-24563 | WordPress Cleanup – Directory Listing & Classifieds plugin <= 1.0.4 - Reflected Cross Site Scripting (XSS) vulnerability | themeglow | Cleanup – Directory Listing & Classifieds WordPress Plugin | High | 7.1 | 2025-01-31 08:24:40 | Deep Dive |
| CVE-2025-23832 | WordPress Admin Cleanup plugin <= 1.0.2 - CSRF to Stored XSS vulnerability | Matt Gibbs | Admin Cleanup | High | 7.1 | 2025-01-16 20:07:14 | Deep Dive |
| CVE-2023-46188 | WordPress Freesoul Deactivate Plugins plugin <= 2.1.3 - Broken Access Control vulnerability | Jose Mortellaro | Freesoul Deactivate Plugins – Plugin manager and cleanup | Medium | 4.3 | 2025-01-02 12:00:00 | Deep Dive |
| CVE-2023-29431 | WordPress qTranslate X Cleanup and WPML Import plugin <= 3.0.1 - Broken Access Control vulnerability | Amir Helzer | qTranslate X Cleanup and WPML Import | Medium | 4.3 | 2024-12-09 11:31:09 | Deep Dive |
| CVE-2024-53738 | WordPress Asset CleanUp: Page Speed Booster plugin <=1.3.9.8 - Server Side Request Forgery (SSRF) vulnerability | Gabe Livan | Asset CleanUp: Page Speed Booster | Medium | 4.4 | 2024-11-30 20:48:33 | Deep Dive |
| CVE-2024-7229 | Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability | Avast | Cleanup Premium | 高危 | - | 2024-11-22 21:11:48 | Deep Dive |
| CVE-2024-7231 | Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability | Avast | Cleanup Premium | 高危 | - | 2024-11-22 21:11:44 | Deep Dive |
| CVE-2024-7230 | Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability | Avast | Cleanup Premium | 高危 | - | 2024-11-22 21:11:41 | Deep Dive |
| CVE-2024-43314 | WordPress Asset CleanUp: Page Speed Booster plugin <= 1.3.9.3 - Broken Access Control vulnerability | Gabe Livan | Asset CleanUp: Page Speed Booster | Medium | 4.3 | 2024-11-01 14:17:26 | Deep Dive |
| CVE-2024-9455 | WP Cleanup and Basic Functions <= 2.2.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | guillaume-lostweb | WP Cleanup and Basic Functions | Medium | 6.4 | 2024-10-05 01:59:41 | Deep Dive |
| CVE-2023-22687 | WordPress Freesoul Deactivate Plugins – Plugin manager and cleanup Plugin <= 1.9.4.0 is vulnerable to Sensitive Data Exposure | Jose Mortellaro | Freesoul Deactivate Plugins – Plugin manager and cleanup | Low | 3.7 | 2023-04-16 08:08:23 | Deep Dive |
| CVE-2021-36899 | WordPress Asset CleanUp: Page Speed Booster plugin <= 1.3.8.4 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability | Gabe Livan | Asset CleanUp: Page Speed Booster (WordPress plugin) | Medium | 4.8 | 2022-10-11 17:02:10 | Deep Dive |
| CVE-2021-24983 | Asset CleanUp < 1.3.8.5 - Reflected Cross-Site Scripting via AJAX Action | Unknown | Asset CleanUp: Page Speed Booster | 中危 | - | 2022-02-01 12:21:34 | Deep Dive |
| CVE-2021-24937 | Asset CleanUp < 1.3.8.5 - Reflected Cross-Site Scripting | Unknown | Asset CleanUp: Page Speed Booster | 中危 | - | 2022-02-01 12:21:32 | Deep Dive |