Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

sevenspark — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting sevenspark. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Sevenspark develops web applications and content management systems, primarily serving digital agencies and businesses requiring custom online solutions. Historically, their products have been susceptible to multiple remote code execution vulnerabilities, cross-site scripting (XSS), and privilege escalation flaws, with 10 CVEs documented to date. Notable security characteristics include inconsistent input validation and insufficient access controls in several components. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities across different products suggests systemic security challenges in their development practices, particularly regarding secure coding standards and timely patch management.

Found 2 results / 13 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-5116 Contact Form 7 – Dynamic Text Extension <= 5.0.5 - Authenticated (Editor+) Stored Cross-Site Scripting — DTX – Dynamic Text Extension for Contact Form 7 CWE-79 4.4 Medium 2026-08-05
CVE-2025-13146 Contact Form 7 – Dynamic Text Extension <= 5.0.7 - Unauthenticated Arbitrary Shortcode Execution — DTX – Dynamic Text Extension for Contact Form 7 CWE-94 6.5 Medium 2026-07-22

This page lists every published CVE security advisory associated with sevenspark. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.