Browse all 8 CVE security advisories affecting Trustindex. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Trustindex operates as a customer review platform that aggregates and displays user-generated feedback across various websites. Historically, the service has been associated with multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, with eight CVEs documented to date. These vulnerabilities often stem from improper input validation and insecure direct object references, potentially allowing attackers to compromise review data or gain unauthorized access. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities suggests ongoing challenges in secure coding practices, particularly in handling user-generated content and access controls.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-14726 | Widgets for Social Photo Feed <= 1.8 - Missing Authentication to Unauthenticated Plugin Settings Access/Update via trustindex_feed_hook_instagram REST API endpoints — Widgets for Social Photo FeedCWE-200 | 6.5 | Medium | 2026-05-02 |
| CVE-2026-5425 | Widgets for Social Photo Feed <= 1.7.9 - Unauthenticated Stored Cross-Site Scripting via feed_data — Widgets for Social Photo FeedCWE-79 | 7.2 | High | 2026-04-04 |
| CVE-2025-68595 | WordPress Widgets for Social Photo Feed plugin <= 1.8 - Broken Access Control vulnerability — Widgets for Social Photo FeedCWE-862 | 5.3 | Medium | 2025-12-24 |
This page lists every published CVE security advisory associated with Trustindex. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.