Known Vulnerabilities for products from Cleantalk

Listed below are 9 of the newest known vulnerabilities associated with the vendor "Cleantalk".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-3213 json Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by Cle... Not Provided 2026-03-25 2026-03-31
CVE-2023-5239 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2023-11-27 2023-12-01
CVE-2022-28222 json The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST[... 6.1 - MEDIUM 2022-04-19 2022-04-28
CVE-2022-28221 json The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST[... 6.1 - MEDIUM 2022-04-19 2022-04-28
CVE-2022-3302 json The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them ... 7.2 - HIGH 2022-10-25 2022-10-26
CVE-2021-24295 json It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, ... 7.5 - HIGH 2021-05-17 2021-05-24
CVE-2021-24131 json Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL i... 7.2 - HIGH 2021-03-18 2021-03-24
CVE-2020-36698 json The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up t... Not Provided 2023-10-20 2026-04-08
CVE-2019-17515 json The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impa... 6.1 - MEDIUM 2019-11-13 2019-11-18

Known software with vulnerabilities from Cleantalk

Type Vendor Product Version
ApplicationCleantalkAnti-spam5.133
ApplicationCleantalkSpam Protection Antispam Firewall-