User Activity Log

User Activity Log has 11 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; 9 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 6.9, and the most serious one scores 9.1 out of 10. Severity breakdown: 1 critical and 5 high. 2023 was the busiest year with 6 disclosures.

The most common weakness is SQL Injection, behind 4 of the records (36%). Other recurring categories include Missing Authorization, Cross-Site Scripting.

9 of the records (82%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2026.

9 independent researchers contributed these findings, one record each.

Strategic Overview

Avg CVSSMedium
6.9/ 10
Patch Coverage82%
Open

2

Fixed

9

Get automatic notifications for all User Activity Log vulnerabilities before they are exploited.

Most severe open issueCVSS 7.5CVE-2025-11877

User Activity Log <= 2.2 - Unauthenticated Limited Options Update via Failed Login

Read the full analysis

Vulnerability Records

11 records
2026-01-06 19:31CVE-2025-11877
7.5
High
shark3yNo
2026-01-06 00:00CVE-2025-13471
5.3
Medium
Alex Tselevich (nos3curity)No
2024-04-07 00:00CVE-2024-31356
9.1
Critical
Muhammad DaffaYes
2023-08-14 00:00CVE-2023-4279
5.3
Medium
Bartłomiej MarekYes
2023-08-08 00:00CVE-2023-4269
7.5
High
Daniel RufYes
2023-07-24 00:00CVE-2023-3435
7.5
High
Marc-Alexandre MontpasYes
2023-07-14 00:00N/A
8.1
High
AnonymousYes
2023-07-12 00:00CVE-2023-37966
7.2
High
LEE SE HYOUNGYes
2023-05-25 00:00CVE-2023-2761
6.6
Medium
Ilyase DehyYes
2021-08-30 00:00N/A
6.1
Medium
AnonymousYes
Showing 1–10 of 11 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C