SecAlerts
g

geodirectory

Security Risk Profile

47
/100
medium

Security Risk Score

Comprehensive risk assessment based on 18 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 23, 2024 to present

18
Total CVEs
8
Critical+High
0
Exploited
8
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
47/100
medium
🆕 2Fresh (<7d)📈 5 in Last 30 Days

Severity Distribution

Critical
0
High
8
Medium
9
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
3

Age Distribution

Common Weaknesses (CWE)

1
XSS
8
2
SQL Injection
2
3
Infoleak
2
4
Path Traversal
1
5
SSRF
1

Most Affected Products

1. GeoDirectory GeoDirectory6
2. GeoDirectory WordPress plugin2
3. GeoDirectory Events Calendar for GeoDirectory2
4. GeoDirectory WP Business Directory Plugin and Classified Listings Directory2
5. AyeCode Geodirectory Wordpress2

Recent Vulnerabilities

See more →
CVE-2026-104899
CVSS 8.1high

GeoDirectory <= 2.8.187 - Unauthenticated Local File Inclusion via 'design_type' Parameter

Oct 10, 2026🔧 No Patch
CVE-2026-104993
CVSS 6.4medium

GeoDirectory <= 2.8.188 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Contact Email Custom Field

Oct 10, 2026🔧 No Patch
CVE-2026-103913
CVSS 7.5high

GeoDirectory <= 2.8.186 - Unauthenticated SQL Injection via 'latitude' Parameter via Stored Pending Listing

Oct 3, 2026🔧 No Patch
CVE-2026-96766
CVSS 6.4EPSS 0%medium

GeoDirectory <= 2.8.183 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'business_hours' Parameter

Sep 25, 2026🔧 No Patch
CVE-2026-93897
CVSS 6.4medium

GeoDirectory <= 2.8.181 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone')

Sep 25, 2026🔧 No Patch
CVE-2026-66604
CVSS 7.1high

WordPress GeoDirectory plugin <= 2.8.173 - Cross Site Scripting (XSS) vulnerability

Aug 20, 2026🔧 No Patch
CVE-2026-19091
CVSS 8.1high

GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision

Aug 11, 2026🔧 No Patch
CVE-2026-16988
CVSS 7.5high

GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint

Aug 9, 2026🔧 No Patch
CVE-2025-15677
CVSS 3.5low

GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories

Aug 5, 2026🔧 No Patch
CVE-2026-16968
CVSS 6.5medium

GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users

Aug 5, 2026🔧 No Patch

Monitor geodirectory in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

geodirectory Security Vulnerabilities & Risk Score | 18 CVEs | SecAlerts - SecAlerts