Browse all 4 CVE security advisories affecting HappyDevs. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Happydevs develops productivity tools for software development teams, focusing on collaboration platforms and project management solutions. Historically, their products have been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation and access control flaws. While no major public security incidents have been documented, their four recorded CVEs highlight consistent issues with authentication mechanisms and insecure default configurations. The company's security posture appears reactive rather than preventive, with patches typically released only after vulnerabilities are disclosed. Their codebase would benefit from more rigorous security testing and secure-by-design principles to reduce recurring flaw patterns.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-62926 | WordPress TempTool [Show Current Template Info] plugin <= 1.3.1 - Cross Site Scripting (XSS) vulnerability — TempTool [Show Current Template Info]CWE-79 | 6.5 | Medium | 2025-12-21 |
| CVE-2025-62955 | WordPress TempTool [Show Current Template Info] plugin <= 1.3.1 - Sensitive Data Exposure vulnerability — TempTool [Show Current Template Info]CWE-497 | 4.3 | Medium | 2025-12-21 |
| CVE-2024-5669 | XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting — Happy WooCommerce FAQs – Ultimate Product FAQ PluginCWE-862 | 6.4 | Medium | 2024-07-09 |
| CVE-2024-5704 | XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update — Happy WooCommerce FAQs – Ultimate Product FAQ PluginCWE-862 | 4.3 | Medium | 2024-07-09 |
This page lists every published CVE security advisory associated with HappyDevs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.