SecAlerts
dynamiapps logo

dynamiapps

Security Risk Profile

67
/100
high

Security Risk Score

Comprehensive risk assessment based on 20 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 29, 2023 to present

20
Total CVEs
16
Critical+High
0
Exploited
11
Unpatched

Threat Assessment

Avg CVSS
8.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
11
Critical/High
Risk Level
67/100
high
🆕 2Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
6
High
10
Medium
4
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
XSS
4
2
SQL Injection
3
3
Input Validation
1
4
Path Traversal
1
5
Malicious File Upload
1

Most Affected Products

1. DynamiApps Frontend Admin17
2. DynamiApps Frontend Admin Wordpress6
3. DynamiApps WordPress Frontend Admin1
4. DynamiApps Frontend Admin by DynamiApps WordPress plugin1

Recent Vulnerabilities

See more →
CVE-2026-66662
CVSS 9.8critical

WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability

8/6/2026🔧 No Patch
CVE-2026-13609
CVSS 8.8high

Frontend Admin by DynamiApps < 3.29.9 - Unauthenticated Stored Cross-Site Scripting via Form Field

7/31/2026🔧 No Patch
CVE-2026-11867
CVSS 6.5medium

Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization

7/30/2026🔧 No Patch
CVE-2026-10039
CVSS 4.9medium

Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL Injection via 'order' Parameter

5/29/2026🔧 No Patch
CVE-2026-6226
CVSS 8.8high

Frontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration Injection

5/28/2026🔧 No Patch
CVE-2026-7802
CVSS 8.8high

Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter

5/28/2026🔧 No Patch
CVE-2026-6228
CVSS 8.8high

Frontend Admin by DynamiApps <= 3.28.36 - Unauthenticated Privilege Escalation via Edit User Form

5/15/2026🔧 No Patch
CVE-2026-3328
CVSS 7.2high

Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts

3/26/2026🔧 No Patch
CVE-2025-14741
CVSS 9.1critical

Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element

1/9/2026🔧 No Patch
CVE-2025-14937
CVSS 7.2high

Frontend Admin by DynamiApps <= 3.28.23 - Unauthenticated Stored Cross-Site Scripting via 'update_field'

1/9/2026🔧 No Patch

Monitor dynamiapps in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

dynamiapps Security Vulnerabilities & Risk Score | 20 CVEs | SecAlerts - SecAlerts