Relevanssi Premium – A Better Search

Relevanssi Premium – A Better Search has 15 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; all 15 are fixed as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 3 high. 2024 was the busiest year with 7 disclosures.

The most common weakness is Cross-Site Scripting, behind 4 of the records (27%). Other recurring categories include SQL Injection, Missing Authorization.

Every one of the 15 issues recorded for Relevanssi Premium – A Better Search has a vendor fix available, so running the current release closes all known holes.

10 independent researchers contributed these findings, most of them (3) reported by Jack Taylor.

01234567891017.11.2016Today17.11.20168.8Relevanssi Premium < 1.14.6.1 - SQL Injection CVSS 8.8 · 17.11.201619.10.20217.2Relevanssi - A Better Search Free & Premium <= 2.16.3 & 4.14.3 - Stored Cross-Site Scripting CVSS 7.2 · 19.10.202115.02.20226.3Relevanssi – A Better Search < 4.14.6 & Relevanssi – A Better Search Pro < 2.16.5 - Missing Authorization CVSS 6.3 · 15.02.202204.01.20245.3Relevanssi <= 4.21.2 (Free) and < 2.25.0 (Premium) - Missing Authorization to Unauthorized Post Access CVSS 5.3 · 04.01.202431.01.20245.3Relevanssi Pro < 2.25 - Unauthenticated Sensitive Information Exposure CVSS 5.3 · 31.01.202422.02.20245.3Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export CVSS 5.3 · 22.02.202404.04.20245.8Relevanssi – A Better Search <= 4.22.1 - Unauthenticated Second Order CSV Injection CVSS 5.8 · 04.04.20245.3Relevanssi – A Better Search <= 4.22.1 - Missing Authorization to Unauthenticated Count Option Update CVSS 5.3 · 04.04.202415.08.20245.3Relevanssi <= 4.22.2 (Free) and <= 2.25.1 (Premium) - Unauthenticated Information Exposure CVSS 5.3 · 15.08.202417.09.20246.4Relevanssi – A Better Search <= 4.23.0 (Free) and <= 2.26.0 (Premium) - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 17.09.202406.05.20256.1Relevanssi <= 4.24.3 (Free) and <= 2.27.4 (Premium) - Unauthenticated Stored Cross-Site Scripting via Search Highlights CVSS 6.1 · 06.05.202512.05.20257.5Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection CVSS 7.5 · 12.05.202530.05.20254.7Relevanssi <= 4.24.5 (Free) and <= 2.27.6 (Premium) - Unauthenticated Stored Cross-Site Scripting via Excerpt Highlights CVSS 4.7 · 30.05.202517.12.20256.5Relevanssi < 4.26.0 (Free) < 2.29.0 (Premium) - Authenticated (Contributor+) SQL Injection CVSS 6.5 · 17.12.202504.08.20266.5Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection CVSS 6.5 · 04.08.2026

Strategic Overview

Avg CVSSMedium
6.2/ 10
Patch Coverage100%
Open

0

Fixed

15

Get automatic notifications for all Relevanssi Premium – A Better Search vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2016-10949

Relevanssi Premium < 1.14.6.1 - SQL Injection

Read the full analysis

Vulnerability Records

15 records
2026-08-04 16:34CVE-2026-15941
6.5
Medium
darooYes
2025-12-17 00:00CVE-2025-14719
6.5
Medium
Drew Webber (mcdruid)Yes
2025-05-30 14:49CVE-2025-5016
4.7
Medium
Jack TaylorYes
2025-05-12 14:38CVE-2025-4396
7.5
High
Jack TaylorYes
2025-05-06 13:45CVE-2025-4054
6.1
Medium
Jack TaylorYes
2024-09-17 00:00CVE-2024-9021
6.4
Medium
Krugov ArtyomYes
2024-08-15 13:29CVE-2024-7630
5.3
Medium
stealthcopterYes
2024-04-04 00:00CVE-2024-3214
5.8
Medium
Thura Moe Myint (mgthuramoemyint)Yes
2024-04-04 00:00CVE-2024-3213
5.3
Medium
Thura Moe Myint (mgthuramoemyint)Yes
2024-02-22 00:00CVE-2024-1380
5.3
Medium
Krzysztof ZającYes
Showing 1–10 of 15 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C