VendorsMetaphor Creationsdittyall versions
Vulnerabilities

Metaphor Creations Ditty

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2025-8085
Ditty < 3.1.58 - Unauthenticated SSRF
Published 2025-09-08 · Analyzed
8.6EPSS 0.174
CVE-2023-23874
WordPress Ditty Plugin <= 3.0.32 is vulnerable to Cross Site Scripting (XSS)
Published 2023-05-03 · Modified
6.5EPSS 0.004
CVE-2022-0533
Ditty (formerly Ditty News Ticker) < 3.0.15 - Reflected Cross-Site Scripting (XSS)
Published 2022-03-07 · Modified
6.1EPSS 0.018
CVE-2023-4148
Ditty < 3.1.25 - Reflected XSS
Published 2023-09-25 · Modified
6.1EPSS 0.008
CVE-2024-6715
Ditty 3.1.39-3.1.45 - Author+ Stored XSS
Published 2024-08-23 · Analyzed
6.1EPSS 0.003
CVE-2024-3939
Ditty < 3.1.36 - Author+ Stored XSS
Published 2024-05-27 · Analyzed
5.4EPSS 0.004
CVE-2024-6710
Ditty < 3.1.45 - Author+ Stored XSS
Published 2024-08-05 · Analyzed
5.4EPSS 0.004
CVE-2024-9600
Ditty < 3.1.47 - Author+ Stored XSS
Published 2024-11-21 · Analyzed
4.8EPSS 0.004
CVE-2024-13357
Ditty – Responsive News Tickers, Sliders, and Lists < 3.1.52 - Author+ Stored XSS
Published 2025-05-15 · Analyzed
4.8EPSS 0.003
CVE-2024-5575
Ditty < 3.1.43 - Author+ Stored XSS
Published 2024-07-13 · Analyzed
4.7EPSS 0.004