SecAlerts
b

bestwebsoft

Security Risk Profile

43
/100
medium

Security Risk Score

Comprehensive risk assessment based on 92 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 3, 2015 to present

92
Total CVEs
26
Critical+High
0
Exploited
15
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
15
Critical/High
Risk Level
43/100
medium
🆕 2Fresh (<7d)📈 4 in Last 30 Days

Severity Distribution

Critical
5
High
21
Medium
66
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
7

Age Distribution

Common Weaknesses (CWE)

1
XSS
56
2
SQL Injection
9
3
CSRF
7
4
Path Traversal
2
5
Malicious File Upload
2

Most Affected Products

1. Bestwebsoft Contact Form Wordpress11
2. Bestwebsoft Error Log Viewer Wordpress5
3. BestWebSoft Contact Form to DB4
4. Bestwebsoft Visitors Online Wordpress4
5. Bestwebsoft Smtp Wordpress3

Recent Vulnerabilities

See more →
CVE-2026-39772
CVSS 5.3medium

WordPress Captcha by BestWebSoft plugin <= 5.2.8 - Bypass Vulnerability vulnerability

Oct 6, 2026🔧 No Patch
CVE-2026-39745
CVSS 7.1high

WordPress Contact Form to DB by BestWebSoft plugin <= 1.7.6 - Cross Site Scripting (XSS) vulnerability

Oct 6, 2026🔧 No Patch
CVE-2026-94457
CVSS 4.8EPSS 0%medium

WordPress Captcha Code plugin <= 3.32 - Bypass Vulnerability vulnerability

Sep 23, 2026🔧 No Patch
CVE-2026-13359
CVSS 7.2high

Contact Form to DB by BestWebSoft <= 1.7.5 - Unauthenticated Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter

Sep 9, 2026🔧 No Patch
CVE-2026-66592
CVSS 9.3critical

WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.11 - SQL Injection vulnerability

Aug 20, 2026🔧 No Patch
CVE-2026-2497
CVSS 7.2high

Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys

Aug 16, 2026🔧 No Patch
CVE-2026-3618
CVSS 6.4medium

Columns by BestWebSoft <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'columns' Shortcode 'id' Attribute

Apr 8, 2026🔧 No Patch
CVE-2025-63056
CVSS 4.3medium

WordPress Contact Form by BestWebSoft plugin <= 4.3.6 - Broken Access Control vulnerability

Dec 9, 2025🔧 No Patch
CVE-2025-13383
CVSS 6.1medium

Job Board by BestWebSoft <= 1.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via $_GET Array Storage

Nov 25, 2025🔧 No Patch
CVE-2025-9950
CVSS 4.9EPSS 0%medium

Error Log Viewer by BestWebSoft <= 1.1.6 - Authenticated (Administrator+) Arbitrary File Read

Oct 11, 2025🔧 No Patch

Monitor bestwebsoft in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.