Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

VeronaLabs — Vulnerabilities & Security Advisories 44

Browse all 44 CVE security advisories affecting VeronaLabs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

VeronaLabs operates as a provider of specialized software solutions, though specific product details remain obscure in public records. An analysis of its security posture reveals a concerning history, with thirty-four Common Vulnerabilities and Exposures (CVEs) currently documented. These vulnerabilities predominantly span critical classes such as Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws. The high frequency of RCE issues suggests systemic weaknesses in input validation and sandboxing mechanisms within their architecture. While no single catastrophic data breach has been widely publicized, the cumulative impact of these thirty-four entries indicates a persistent struggle with fundamental secure coding practices. This pattern of recurring, high-severity flaws implies that the organization may lack robust automated security testing or rigorous code review processes. Consequently, users and administrators face significant risks when deploying VeronaLabs products, necessitating strict network segmentation and continuous monitoring to mitigate potential exploitation vectors.

CVE ID Title CVSS Severity Published
CVE-2024-2194 WP Statistics <= 14.5 - Unauthenticated Stored Cross-Site Scripting — WP Statistics – Simple, privacy-friendly Google Analytics alternative CWE-79 7.2 High 2024-03-13
CVE-2024-24881 WordPress WP SMS Plugin <= 6.5.2 is vulnerable to Cross Site Scripting (XSS) — WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc CWE-79 7.1 High 2024-02-08
CVE-2024-1073 SlimStat Analytics <= 5.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting — SlimStat Analytics CWE-79 6.4 Medium 2024-02-02
CVE-2023-6981 WP SMS <= 6.5 - Authenticated (Admin+) SQL Injection to Reflected Cross-Site Scripting — WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce CWE-89 6.1 Medium 2024-01-03
CVE-2023-6980 WP SMS <= 6.5 - Cross-Site Request Forgery to Subscriber Deletion — WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce CWE-352 4.3 Medium 2024-01-03
CVE-2023-27447 WordPress WP SMS Plugin <= 6.0.4 is vulnerable to Sensitive Data Exposure — WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc CWE-200 5.3 Medium 2023-12-28
CVE-2023-4598 Slimstat Analytics <= 5.0.9 - Authenticated (Contributor+) Blind SQL Injection via Shortcode — SlimStat Analytics CWE-89 8.8 High 2023-10-20
CVE-2023-32742 WordPress WP SMS Plugin <= 6.1.4 is vulnerable to Cross Site Scripting (XSS) — WP SMS CWE-79 7.1 High 2023-08-30
CVE-2023-4597 Slimstat Analytics <= 5.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — SlimStat Analytics CWE-79 6.4 Medium 2023-08-30
CVE-2022-38074 WordPress WP Statistics Plugin <= 13.2.10 is vulnerable to SQL Injection — WP Statistics CWE-89 9.9 High 2023-03-13
CVE-2021-4333 WP Statistics <= 13.1.1 - Cross-Site Request Forgery to Arbitrary Plugin Activation and Deactivation — WP Statistics – Simple, privacy-friendly Google Analytics alternative CWE-352 6.5 Medium 2023-03-07
CVE-2022-27231 WordPress plugin WP Statistics 跨站脚本漏洞 — WP Statistics 6.1 - 2022-06-13
CVE-2022-0513 WP Statistics <= 13.1.4 Unauthenticated Blind SQL Injection via exclusion_reason — WP Statistics CWE-89 9.8 Critical 2022-02-16
CVE-2021-24340 WP Statistics < 13.0.8 - Unauthenticated SQL Injection — WP Statistics CWE-89 7.5 - 2021-06-07

This page lists every published CVE security advisory associated with VeronaLabs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.