Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Merkulove — Vulnerabilities & Security Advisories 43

Browse all 43 CVE security advisories affecting Merkulove. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Merkulove operates as a specialized provider of cybersecurity solutions, primarily focusing on advanced threat detection and incident response services for enterprise environments. Despite its role in security, the company’s software infrastructure has historically been associated with a significant volume of vulnerabilities, currently totaling forty recorded Common Vulnerabilities and Exposures (CVEs). These security flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation issues, suggesting recurring weaknesses in input validation and access control mechanisms within its deployment architecture. While specific major public breaches directly attributed to Merkulove remain limited in public reporting, the high frequency of disclosed CVEs indicates persistent challenges in maintaining robust code hygiene. This pattern highlights the critical importance of rigorous security testing even for vendors specializing in defensive technologies, as internal vulnerabilities can inadvertently expose client networks to exploitation.

CVE ID Title CVSS Severity Published
CVE-2025-68086 WordPress Reformer for Elementor plugin <= 1.0.6 - Broken Access Control vulnerability — Reformer for Elementor CWE-862 5.4 Medium 2025-12-16
CVE-2025-68088 WordPress Huger for Elementor plugin <= 1.1.5 - Broken Access Control vulnerability — Huger for Elementor CWE-862 5.4 Medium 2025-12-16
CVE-2025-66166 WordPress Lottier for Elementor plugin <= 1.0.9 - Broken Access Control vulnerability — Lottier for Elementor CWE-862 5.4 Medium 2025-12-16
CVE-2025-66167 WordPress Lottier plugin <= 1.1.1 - Broken Access Control vulnerability — Lottier CWE-862 5.4 Medium 2025-12-16
CVE-2025-66164 WordPress Laser plugin <= 1.1.1 - Broken Access Control vulnerability — Laser CWE-862 5.4 Medium 2025-12-16
CVE-2025-66163 WordPress Masker for Elementor plugin <= 1.1.4 - Broken Access Control vulnerability — Masker for Elementor CWE-862 5.4 Medium 2025-12-16
CVE-2025-66162 WordPress Spoter for Elementor plugin <= 1.04 - Broken Access Control vulnerability — Spoter for Elementor CWE-862 5.4 Medium 2025-12-16
CVE-2025-66165 WordPress Lottier for WPBakery plugin <= 1.1.7 - Broken Access Control vulnerability — Lottier for WPBakery CWE-862 5.4 Medium 2025-12-16
CVE-2025-66161 WordPress Grider for Elementor plugin <= 1.0.8 - Broken Access Control vulnerability — Grider for Elementor CWE-862 5.4 Medium 2025-12-16
CVE-2025-66147 WordPress Coder for Elementor plugin <= 1.0.13 - Broken Access Control vulnerability — Coder for Elementor CWE-862 5.4 Medium 2025-12-16
CVE-2025-49444 WordPress Reformer for Elementor plugin <= 1.0.5 - Arbitrary File Upload Vulnerability — Reformer for Elementor CWE-434 10.0 Critical 2025-06-17
CVE-2024-50445 WordPress Selection Lite plugin <= 1.13 - Cross Site Scripting (XSS) vulnerability — Selection Lite CWE-79 6.5 Medium 2024-10-28
CVE-2024-43147 WordPress Selection Lite plugin <= 1.11 - Cross Site Scripting (XSS) vulnerability — Selection Lite CWE-79 6.5 Medium 2024-08-12

This page lists every published CVE security advisory associated with Merkulove. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.