SecAlerts
c

cleantalk

Security Risk Profile

51
/100
medium

Security Risk Score

Comprehensive risk assessment based on 20 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from November 13, 2019 to present

20
Total CVEs
15
Critical+High
0
Exploited
9
Unpatched

Threat Assessment

Avg CVSS
7.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
9
Critical/High
Risk Level
51/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
3
High
12
Medium
5
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
XSS
7
2
SQL Injection
4
3
CSRF
2
4
Malicious File Upload
1

Most Affected Products

1. CleanTalk Spam Protection\, Antispam\, Firewall Wordpress5
2. CleanTalk Anti-Spam by CleanTalk3
3. CleanTalk Security \& Malware Scan Wordpress3
4. CleanTalk Spam protection, Anti-Spam, FireWall3
5. CleanTalk Anti-spam Wordpress3

Recent Vulnerabilities

See more →
CVE-2026-77830
CVSS 7.2high

Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder

Sep 5, 2026🔧 No Patch
CVE-2026-10770
CVSS 6.1medium

Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042

Jul 10, 2026🔧 No Patch
CVE-2026-8071
CVSS 8.8high

Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass

Jun 10, 2026🔧 No Patch
CVE-2026-3213
CVSS 4.7medium

Anti-Spam by CleanTalk - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-014

Mar 25, 2026🔧 No Patch
CVE-2026-1490
CVSS 9.8critical

Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation

Feb 15, 2026🔧 No Patch
CVE-2024-13365
CVSS 9.8critical

Security & Malware scan by CleanTalk <= 2.149 - Unauthenticated Arbitrary File Upload

Feb 12, 2025
CVE-2023-33996
CVSS 8.8high

WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 6.10 - Broken Access Control vulnerability

Dec 13, 2024
CVE-2024-10542
CVSS 9.8critical

Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation

Nov 26, 2024
CVE-2024-10781
CVSS 8.1high

Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.44 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Arbitrary Plugin Installation

Nov 26, 2024
CVE-2024-10570
CVSS 7.5high

Security & Malware scan by CleanTalk <= 2.145 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated SQL Injection

Nov 26, 2024🔧 No Patch

Monitor cleantalk in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

cleantalk Security Vulnerabilities & Risk Score | 20 CVEs | SecAlerts - SecAlerts