SecAlerts
b

bestwebsoft

Security Risk Profile

52
/100
medium

Security Risk Score

Comprehensive risk assessment based on 89 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 3, 2015 to present

89
Total CVEs
25
Critical+High
0
Exploited
14
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
14
Critical/High
Risk Level
52/100
medium
🆕 1Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
5
High
20
Medium
64
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
55
2
SQL Injection
9
3
CSRF
7
4
Path Traversal
2
5
Malicious File Upload
2

Most Affected Products

1. Bestwebsoft Contact Form Wordpress11
2. Bestwebsoft Error Log Viewer Wordpress5
3. BestWebSoft Contact Form to DB4
4. Bestwebsoft Visitors Online Wordpress4
5. Bestwebsoft Smtp Wordpress3

Recent Vulnerabilities

See more →
CVE-2026-13359
CVSS 7.2high

Contact Form to DB by BestWebSoft <= 1.7.5 - Unauthenticated Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter

Sep 9, 2026🔧 No Patch
CVE-2026-66592
CVSS 9.3critical

WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.11 - SQL Injection vulnerability

Aug 20, 2026🔧 No Patch
CVE-2026-2497
CVSS 7.2high

Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys

Aug 16, 2026🔧 No Patch
CVE-2026-3618
CVSS 6.4medium

Columns by BestWebSoft <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'columns' Shortcode 'id' Attribute

Apr 8, 2026🔧 No Patch
CVE-2025-63056
CVSS 4.3medium

WordPress Contact Form by BestWebSoft plugin <= 4.3.6 - Broken Access Control vulnerability

Dec 9, 2025🔧 No Patch
CVE-2025-13383
CVSS 6.1medium

Job Board by BestWebSoft <= 1.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via $_GET Array Storage

Nov 25, 2025🔧 No Patch
CVE-2025-9950
CVSS 4.9EPSS 0%medium

Error Log Viewer by BestWebSoft <= 1.1.6 - Authenticated (Administrator+) Arbitrary File Read

Oct 11, 2025🔧 No Patch
CVE-2025-39527
CVSS 8.8EPSS 0%high

WordPress Rating by BestWebSoft plugin <= 1.7 - PHP Object Injection Vulnerability

Apr 17, 2025🔧 No Patch
CVE-2025-31099
CVSS 7.6EPSS 0%high

WordPress Slider by BestWebSoft plugin <= 1.1.0 - SQL Injection Vulnerability

Mar 28, 2025
CVE-2024-13908
CVSS 7.2high

SMTP by BestWebSoft <= 1.1.9 - Authenticated (Administrator+) Arbitrary File Upload

Mar 8, 2025

Monitor bestwebsoft in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

bestwebsoft Security Vulnerabilities & Risk Score | 89 CVEs | SecAlerts - SecAlerts