sharethis records
7 published records for vendor sharethis.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 14.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2014-4717Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote atsharethis · simple share buttons adder · CWE-352 | Medium6.8 | — | 2.8% | Jul 3, 2014 |
27Monitor | CVE-2013-3479No exploit | Cross-site request forgery (CSRF) vulnerability in the ShareThis plugin before 7.0.6 for WordPress allows remote attackers to hijack the autsharethis · sharethis · CWE-352 | Medium6.8 | — | 1.2% | Sep 4, 2013 |
24Monitor | CVE-2021-24438No exploit | ShareThis Dashboard for Google Analytics < 2.5.2 - Reflected Cross-Site Scripting (XSS)sharethis · dashboard for google analytics · CWE-79 | Medium6.1 | — | 0.8% | Aug 30, 2021 |
21Monitor | CVE-2024-4094No exploit | Simple Share Buttons Adder < 8.5.1 - Admin+ Stored XSSsharethis · simple share buttons adder · CWE-79 | Medium5.4 | — | 0.4% | Jun 18, 2024 |
21Monitor | CVE-2025-1507No exploit | ShareThis Dashboard for Google Analytics <= 3.2.1 - Missing Authorization to Unauthenticated Feature Deactivationsharethis · dashboard for google analytics · CWE-862 | Medium5.3 | — | 0.3% | Mar 14, 2025 |
21Monitor | CVE-2024-3648No exploit | ShareThis Share Buttons <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via sharethis-inline-buttons Shortcodesharethis · sharethis share buttons · CWE-79 | Medium5.4 | — | 0.3% | May 23, 2024 |
19Monitor | CVE-2021-36848No exploit | WordPress Social Media Feather plugin <= 2.0.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitysharethis · social media feather · CWE-79 | Medium4.8 | — | 0.6% | Apr 11, 2022 |
- CVE-2014-471728Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote at
MediumCVSS 6.8Proof of conceptEPSS 3%sharethis · simple share buttons adderJul 3, 2014
- CVE-2013-347927Monitor
Cross-site request forgery (CSRF) vulnerability in the ShareThis plugin before 7.0.6 for WordPress allows remote attackers to hijack the aut
MediumCVSS 6.8No exploitEPSS 1%sharethis · sharethisSep 4, 2013
- CVE-2021-2443824Monitor
ShareThis Dashboard for Google Analytics < 2.5.2 - Reflected Cross-Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 1%sharethis · dashboard for google analyticsAug 30, 2021
- CVE-2024-409421Monitor
Simple Share Buttons Adder < 8.5.1 - Admin+ Stored XSS
MediumCVSS 5.4No exploitEPSS 0%sharethis · simple share buttons adderJun 18, 2024
- CVE-2025-150721Monitor
ShareThis Dashboard for Google Analytics <= 3.2.1 - Missing Authorization to Unauthenticated Feature Deactivation
MediumCVSS 5.3No exploitEPSS 0%sharethis · dashboard for google analyticsMar 14, 2025
- CVE-2024-364821Monitor
ShareThis Share Buttons <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via sharethis-inline-buttons Shortcode
MediumCVSS 5.4No exploitEPSS 0%sharethis · sharethis share buttonsMay 23, 2024
- CVE-2021-3684819Monitor
WordPress Social Media Feather plugin <= 2.0.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 1%sharethis · social media featherApr 11, 2022