Home/Product/podsfoundation pods
Product

podsfoundation pods

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-1446
< 3.2.8.2
The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing ad
9.8CRITICAL
CVE-2024-11849
< 3.2.8.1
The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege user
6.1MEDIUM
CVE-2024-9883
< 3.2.7.1
The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege user
4.8MEDIUM
CVE-2023-6999
< 2.7.31.2
The Pods - Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versi
8.8HIGH
CVE-2023-6967
< 2.7.31.2
The Pods - Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to
8.8HIGH
CVE-2023-6965
< 2.7.31.2
The Pods - Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and
4.3MEDIUM
CVE-2023-23790
< 2.9.11
Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods - Custom Content Types and Fields plugin <= 2.9.10.2
7.1HIGH
CVE-2021-24339
< 2.7.27
The Pods - Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scr
5.4MEDIUM
CVE-2021-24338
< 2.7.27
The Pods - Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scr
5.4MEDIUM
CVE-2014-7957
<= 2.4.3
Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to h
CVE-2014-7956
<= 2.4.3
Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject arbitrary w
threatengine.sh