Profilegrid
This hub aggregates every CVE we track for Profilegrid, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
45
CVEs tracked
1
Critical
14
High
0
In CISA KEV
Severity distribution
MEDIUM30HIGH14CRITICAL1
Monthly trend
2
0
1
1
2
0
0
2
4
1
2
2
2
1
1
0
0
0
0
0
1
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Profilegrid.
- CVE-2026-25417WordPress ProfileGrid plugin <= 5.9.8.1 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2025-4957WordPress ProfileGrid plugin <= 5.9.5.7 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2025-49033WordPress ProfileGrid plugin <= 5.9.5.3 - SQL Injection vulnerability8.5
- CVE-2025-49876WordPress ProfileGrid plugin <= 5.9.5.2 - SQL Injection vulnerability8.5
- CVE-2025-6977ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function6.1
- CVE-2025-52719WordPress ProfileGrid plugin <= 5.9.5.2 - Full Path Disclosure (FPD) Vulnerability4.3
- CVE-2025-49877WordPress ProfileGrid plugin <= 5.9.5.2 - Server Side Request Forgery (SSRF) Vulnerability4.9
- CVE-2025-47478WordPress ProfileGrid plugin <= 5.9.5.0 - SQL Injection Vulnerability8.5
- CVE-2025-48079WordPress ProfileGrid plugin <= 5.9.5.1 - Broken Access Control Vulnerability4.3
- CVE-2025-39586WordPress ProfileGrid plugin <= 5.9.4.8 - SQL Injection Vulnerability8.5
- CVE-2025-0724ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object Injection8.8
- CVE-2025-1408ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.4 - Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management4.3
- CVE-2025-0723ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.7 - Authenticated (Subscriber+) SQL Injection6.5
- CVE-2025-26999WordPress ProfileGrid Plugin <= 5.9.4.3 - PHP Object Injection vulnerability8.8
- CVE-2024-13740ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure4.3
Product normalization is registry-driven with AI assist and human review. How it works