Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Metagauss Subscribe
Filtered by product Profilegrid
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-41791 1 Metagauss 1 Profilegrid 2022-11-21 N/A 8.8 HIGH
Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.
CVE-2022-3578 1 Metagauss 1 Profilegrid 2022-11-16 N/A 6.1 MEDIUM
The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-0233 1 Metagauss 1 Profilegrid 2022-01-24 3.5 LOW 5.4 MEDIUM
The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user access, such as subscribers, to inject arbitrary web scripts into their profile, in versions up to and including 1.2.7.
CVE-2019-15873 1 Metagauss 1 Profilegrid 2022-01-24 6.5 MEDIUM 8.8 HIGH
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code.