Known vulnerabilities in Canto
Find & publish creative assets to WordPress easily, no email or folder search needed, with Canto's digital asset management.
9Reported vulnerabilities
9.8Highest CVSS score
3.1.3Latest version
100+Active installs
What to do now
Update Canto to 3.1.2 or later.
9 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2020-28976 | Medium | 27.8% | 1.3.0 to 1.3.0 (inclusive) | 2.0.1 |
November 30, 2020 |
| CVE-2023-3452 | Critical | 7.0% | 3.0.4 and earlier | 3.0.5 |
August 12, 2023 |
| CVE-2020-28978 | Medium | 15.4% | 1.3.0 to 1.3.0 (inclusive) | 2.0.1 |
November 30, 2020 |
| CVE-2020-28977 | Medium | 15.4% | 1.3.0 to 1.3.0 (inclusive) | 2.0.1 |
November 30, 2020 |
| CVE-2024-4936 | Critical | 1.0% | Before 3.0.9 | 3.0.9 |
June 14, 2024 |
| CVE-2024-25096 | Critical | 0.7% | 3.0.6 and earlier | 3.0.7 |
February 12, 2024 |
| CVE-2020-24063 | High | 1.5% | 1.3.0 to 1.3.0 (inclusive) | 2.0.1 |
November 10, 2020 |
| CVE-2026-3335 | Medium | 1.1% | 0 to 3.1.1 (inclusive) | 3.1.2 |
March 21, 2026 |
| CVE-2026-6441 | Medium | 0.3% | 0 to 3.1.1 (inclusive) | 3.1.2 |
April 17, 2026 |