Browse all 4 CVE security advisories affecting dugudlabs. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Dugudlabs develops security tools and research, primarily focusing on vulnerability assessment and penetration testing. Their recorded CVEs reveal a pattern of remote code execution and cross-site scripting vulnerabilities in their products, with occasional privilege escalation flaws. While no major public security incidents have been documented, their vulnerability history suggests consistent issues in input validation and access control mechanisms. The organization maintains a moderate CVE count, indicating manageable but recurring security challenges in their software development lifecycle. Their work primarily serves security professionals and organizations seeking to identify and remediate weaknesses in their systems.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-14365 | Eyewear prescription form <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary WooCommerce Category Deletion — Eyewear prescription formCWE-862 | 5.3 | Medium | 2025-12-13 |
| CVE-2025-14366 | Eyewear prescription form <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary WooCommerce Product Creation — Eyewear prescription formCWE-862 | 5.3 | Medium | 2025-12-13 |
| CVE-2025-23973 | WordPress SpecFit-Virtual Try On Woocommerce plugin <= 8.0.3 - Cross Site Scripting (XSS) vulnerability — SpecFit-Virtual Try On WoocommerceCWE-79 | 7.1 | High | 2025-06-27 |
| CVE-2024-54239 | WordPress Eyewear prescription form plugin <= 4.0.18 - Arbitrary Option Update to Privilege Escalation vulnerability — Eyewear prescription formCWE-862 | 9.8 | Critical | 2024-12-13 |
This page lists every published CVE security advisory associated with dugudlabs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.