Post grid
This hub aggregates every CVE we track for Post grid, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
23
CVEs tracked
0
Critical
10
High
0
In CISA KEV
Severity distribution
MEDIUM13HIGH10
Monthly trend
1
1
0
0
1
2
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Post grid.
- CVE-2024-9645Post Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSS5.4
- CVE-2024-13796Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure5.3
- CVE-2024-13798Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation5.3
- CVE-2024-13408Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion7.5
- CVE-2021-4450Post Grid <= 2.1.12 - Contributor+ SQL Injection8.8
- CVE-2024-8253Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation8.8
- CVE-2024-7588Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block6.4
- CVE-2024-6346Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget6.4
- CVE-2024-4042Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute6.4
- CVE-2024-1988Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
- CVE-2024-3155Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
- CVE-2024-32816WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerability7.5
- CVE-2024-0881Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access5.4
- CVE-2024-30441WordPress Combo Blocks plugin <= 2.2.74 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2023-7072Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint7.5
Product normalization is registry-driven with AI assist and human review. How it works