pixelimity records
7 published records for vendor pixelimity.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-28590Proof of concept | A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme.pixelimity · pixelimity | High7.2 | — | 23.8% | May 3, 2022 |
28Monitor | CVE-2020-23522Proof of concept | Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.pixelimity · pixelimity · CWE-352 | Medium6.8 | — | 2.0% | Jan 19, 2021 |
20Monitor | CVE-2025-5206No exploit | Pixelimity Installation index.php sql injectionpixelimity · pixelimity · CWE-74 | Medium5.1 | — | 0.4% | May 26, 2025 |
19Monitor | CVE-2018-19919No exploit | Pixelimity 1.0 has Persistent XSS via the admin/portfolio.php data[title] parameter, as demonstrated by a crafted onload attribute of an SVGpixelimity · pixelimity · CWE-79 | Medium4.8 | — | 0.7% | Dec 6, 2018 |
19Monitor | CVE-2022-28589No exploit | A stored cross-site scripting (XSS) vulnerability in Pixelimity 1.0 allows attackers to execute arbitrary web scripts or HTML via the Title pixelimity · pixelimity · CWE-79 | Medium4.8 | — | 0.6% | May 3, 2022 |
19Monitor | CVE-2021-42866No exploit | A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.phppixelimity · pixelimity · CWE-79 | Medium4.8 | — | 0.6% | Mar 31, 2022 |
19Monitor | CVE-2021-29056No exploit | Cross Site Scripting (XSS) vulnerability exists in Pixelimity 1.0 via the HTTP POST parameter to admin/setting.php.pixelimity · pixelimity · CWE-79 | Medium4.8 | — | 0.5% | Aug 17, 2021 |
- CVE-2022-2859035Monitor
A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme.
HighCVSS 7.2Proof of conceptEPSS 24%pixelimity · pixelimityMay 3, 2022
- CVE-2020-2352228Monitor
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
MediumCVSS 6.8Proof of conceptEPSS 2%pixelimity · pixelimityJan 19, 2021
- CVE-2025-520620Monitor
Pixelimity Installation index.php sql injection
MediumCVSS 5.1No exploitEPSS 0%pixelimity · pixelimityMay 26, 2025
- CVE-2018-1991919Monitor
Pixelimity 1.0 has Persistent XSS via the admin/portfolio.php data[title] parameter, as demonstrated by a crafted onload attribute of an SVG
MediumCVSS 4.8No exploitEPSS 1%pixelimity · pixelimityDec 6, 2018
- CVE-2022-2858919Monitor
A stored cross-site scripting (XSS) vulnerability in Pixelimity 1.0 allows attackers to execute arbitrary web scripts or HTML via the Title
MediumCVSS 4.8No exploitEPSS 1%pixelimity · pixelimityMay 3, 2022
- CVE-2021-4286619Monitor
A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php
MediumCVSS 4.8No exploitEPSS 1%pixelimity · pixelimityMar 31, 2022
- CVE-2021-2905619Monitor
Cross Site Scripting (XSS) vulnerability exists in Pixelimity 1.0 via the HTTP POST parameter to admin/setting.php.
MediumCVSS 4.8No exploitEPSS 1%pixelimity · pixelimityAug 17, 2021