Known Vulnerabilities for products from Cozmoslabs

Listed below are 12 of the newest known vulnerabilities associated with the vendor "Cozmoslabs".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-58600 Not Provided 2025-09-03 2026-04-01
CVE-2025-54017 Not Provided 2025-08-20 2026-04-01
CVE-2025-49870 Not Provided 2025-07-04 2026-04-01
CVE-2025-49292 Not Provided 2025-06-06 2026-04-01
CVE-2025-31088 Not Provided 2025-03-28 2026-04-01
CVE-2025-30773 Not Provided 2025-03-27 2026-04-01
CVE-2021-36915 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 4.3 - MEDIUM 2022-10-11 2022-10-13
CVE-2021-24728 The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate o... 8.8 - HIGH 2021-09-13 2022-12-20
CVE-2021-24610 The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp... 4.8 - MEDIUM 2021-09-27 2021-10-04
CVE-2021-24527 The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset t... 9.8 - CRITICAL 2021-08-16 2023-11-07
CVE-2021-24473 The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image ca... 5.4 - MEDIUM 2021-08-02 2021-09-20
CVE-2021-24448 The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modif... 4.8 - MEDIUM 2021-08-02 2023-11-07
CVE-2021-24170 The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was ... 7.5 - HIGH 2021-04-05 2021-04-09
CVE-2016-10911 The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues. 6.1 - MEDIUM 2019-08-21 2019-08-22
CVE-2015-9337 The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX. 7.5 - HIGH 2019-08-22 2019-08-26
CVE-2015-9328 The profile-builder plugin before 2.2.5 for WordPress has XSS. 6.1 - MEDIUM 2019-08-21 2019-08-22
CVE-2014-10380 The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms. 6.1 - MEDIUM 2019-08-21 2019-08-22
CVE-2014-8492 Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0... 6.1 - MEDIUM 2017-10-06 2017-10-13

Known software with vulnerabilities from Cozmoslabs

Type Vendor Product Version
ApplicationCozmoslabsProfile Builder1.0