Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

realmag777 — Vulnerabilities & Security Advisories 122

Browse all 122 CVE security advisories affecting realmag777. AI-powered Chinese analysis, POCs, and references for each vulnerability.

realmag777 is a software vendor primarily known for developing and distributing e-commerce solutions and digital marketplace platforms. Historical security audits reveal a pattern of critical vulnerabilities, with 109 CVEs currently on record. The most prevalent flaw classes include Remote Code Execution (RCE) and Cross-Site Scripting (XSS), often stemming from insufficient input validation and improper sanitization of user-supplied data. Additionally, the software has frequently exhibited insecure direct object references and privilege escalation issues, allowing unauthorized users to access sensitive administrative functions or modify system configurations. These defects typically arise from legacy codebases that lack modern security controls and regular patching cycles. Major incidents have involved data breaches exposing customer personal information and payment details due to unpatched SQL injection flaws. The high volume of disclosed vulnerabilities suggests a reactive rather than proactive security posture, requiring immediate attention to code review processes and dependency management to mitigate ongoing risks for enterprise clients relying on this infrastructure.

CVE ID Title CVSS Severity Published
CVE-2025-57889 WordPress InPost Gallery Plugin <= 2.1.4.5 - Local File Inclusion Vulnerability — InPost Gallery CWE-98 7.5 High 2025-09-05
CVE-2025-54707 WordPress MDTF Plugin <= 1.3.3.7 - SQL Injection Vulnerability — MDTF CWE-89 9.3 Critical 2025-08-14
CVE-2025-52732 WordPress Google Map Targeting Plugin <= 1.1.6 - Local File Inclusion Vulnerability — GMap Targeting CWE-98 8.8 High 2025-08-14
CVE-2025-5143 TableOn – WordPress Posts Table Filterable <= 1.0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via tableon_popup_iframe_button Shortcode — TableOn – WordPress Posts Table Filterable CWE-79 6.4 Medium 2025-06-21
CVE-2025-52708 WordPress HUSKY plugin <= 1.3.7 - Local File Inclusion Vulnerability — HUSKY CWE-98 7.5 High 2025-06-20
CVE-2025-48266 WordPress Active Products Tables for WooCommerce plugin <= 1.0.6.8 - Cross Site Scripting (XSS) Vulnerability — Active Products Tables for WooCommerce CWE-79 6.5 Medium 2025-05-19
CVE-2025-3748 Taxonomy Chain Menu <= 1.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via pn_chain_menu Shortcode — Taxonomy Chain Menu CWE-79 6.4 Medium 2025-05-02
CVE-2025-32592 WordPress TableOn Plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerability — TableOn CWE-79 7.1 High 2025-04-17
CVE-2025-26903 WordPress InPost Gallery plugin <= 2.1.4.3 - Cross Site Request Forgery (CSRF) vulnerability — InPost Gallery CWE-352 4.3 Medium 2025-04-15
CVE-2025-32569 WordPress TableOn plugin <= 1.0.4.3 - PHP Object Injection vulnerability — TableOn CWE-502 9.8 Critical 2025-04-11
CVE-2025-32218 WordPress TableOn plugin <= 1.0.5.1 - Broken Access Control vulnerability — TableOn CWE-862 5.4 Medium 2025-04-04
CVE-2025-26890 WordPress HUSKY plugin <= 1.3.6.4 - Local File Inclusion vulnerability — HUSKY CWE-98 7.5 High 2025-03-27
CVE-2025-1514 Active Products Tables for WooCommerce <= 1.0.6.7 - Unauthenticated Arbitrary Filter Call — Active Products Tables for WooCommerce. Use constructor to create tables CWE-20 7.3 High 2025-03-26
CVE-2025-2169 WPCS – WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution — WPCS – WordPress Currency Switcher Professional CWE-94 7.3 High 2025-03-11
CVE-2025-1661 HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion — HUSKY – Products Filter Professional for WooCommerce CWE-22 9.8 Critical 2025-03-11
CVE-2025-0864 Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.6 - Reflected Cross-Site Scripting — Active Products Tables for WooCommerce. Use constructor to create tables CWE-79 6.1 Medium 2025-02-18
CVE-2025-26775 WordPress BEAR Plugin <= 1.1.4.4 - Cross Site Scripting (XSS) vulnerability — BEAR CWE-79 5.9 Medium 2025-02-17
CVE-2025-24605 WordPress WOLF plugin <= 1.0.8.5 - Path Traversal vulnerability — WOLF CWE-22 7.5 Medium 2025-02-03
CVE-2024-13340 MDTF – Meta Data and Taxonomies Filter <= 1.3.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting — MDTF – Meta Data and Taxonomies Filter CWE-79 6.4 Medium 2025-01-23
CVE-2024-12030 MDTF – Meta Data and Taxonomies Filter <= 1.3.3.5 - Authenticated (Contributor+) SQL Injection — MDTF – Meta Data and Taxonomies Filter CWE-89 6.5 Medium 2025-01-08
CVE-2023-40334 WordPress HUSKY plugin <= 1.3.4.2 - Broken Access Control vulnerability — HUSKY CWE-862 4.3 Medium 2024-12-13
CVE-2024-10959 Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.5 - Unauthenticated Arbitrary Shortcode Execution via woot_get_smth — Active Products Tables for WooCommerce. Use constructor to create tables CWE-94 7.3 High 2024-12-10
CVE-2024-11002 InPost Gallery <= 2.1.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template — InPost Gallery CWE-94 6.3 Medium 2024-11-26
CVE-2024-11400 HUSKY – Products Filter for WooCommerce <= 1.3.6.3 - Reflected Cross-Site Scripting via really_curr_tax Parameter — HUSKY – Products Filter Professional for WooCommerce CWE-79 6.1 Medium 2024-11-19
CVE-2024-52396 WordPress WOLF plugin <= 1.0.8.3 - CSV Limited Path Traversal vulnerability — WOLF CWE-22 4.9 Medium 2024-11-14
CVE-2024-10640 The FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution — FOX – Currency Switcher Professional for WooCommerce CWE-94 7.3 High 2024-11-09
CVE-2024-10168 Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode — Active Products Tables for WooCommerce. Use constructor to create tables CWE-79 6.4 Medium 2024-11-06
CVE-2024-50451 WordPress MDTF – Meta Data and Taxonomies Filter plugin <= 1.3.3.4 - Cross Site Scripting (XSS) vulnerability — MDTF CWE-79 6.5 Medium 2024-10-28
CVE-2024-50450 WordPress MDTF – Meta Data and Taxonomies Filter plugin <= 1.3.3.4 - Bypass Vulnerability vulnerability — MDTF CWE-94 7.3 High 2024-10-28
CVE-2024-7491 HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.1 - Insecure Direct Object Reference to Unsubscribe — HUSKY – Products Filter Professional for WooCommerce CWE-862 5.3 Medium 2024-09-25

This page lists every published CVE security advisory associated with realmag777. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.