All 4 CVE vulnerabilities found in Optimole – Optimize Images in Real Time, with AI-generated Chinese analysis, references, and POCs.
Vendor: optimole
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-5217 | Optimole <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Parameter CWE-79 | 7.2 | High | 2026-04-11 |
| CVE-2026-5226 | Optimole <= 4.2.3 - Reflected Cross-Site Scripting via Page Profiler URL CWE-79 | 6.1 | Medium | 2026-04-11 |
| CVE-2025-11519 | Image optimization service by Optimole <= 4.1.0 - Insecure Direct Object Reference to Authenticated (Author+) Media Offload CWE-639 | 4.3 | Medium | 2025-10-18 |
| CVE-2024-4636 | Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF <= 3.12.10 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload CWE-79 | 6.4 | Medium | 2024-05-15 |
All 4 known CVE vulnerabilities affecting Optimole – Optimize Images in Real Time with full Chinese analysis, references, and POCs where available.