Known Vulnerabilities for products from Custom Field Suite Project
Listed below are 8 of the newest known vulnerabilities associated with the vendor "Custom Field Suite Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2024-3562 json | The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 v... | Not Provided | 2024-06-20 | 2026-04-08 |
| CVE-2024-3561 json | The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up... | Not Provided | 2024-06-20 | 2026-04-08 |
| CVE-2024-3559 json | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' para... | Not Provided | 2024-06-12 | 2026-04-08 |
| CVE-2024-3558 json | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' parame... | Not Provided | 2024-06-20 | 2026-04-08 |
| CVE-2024-3068 json | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' param... | Not Provided | 2024-05-14 | 2026-04-08 |
| CVE-2024-0689 json | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versions up... | Not Provided | 2024-02-29 | 2026-04-08 |
| CVE-2023-32515 json | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versions. | 4.8 - MEDIUM | 2023-05-18 | 2023-05-25 |
| CVE-2019-11871 json | The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins. | 5.4 - MEDIUM | 2019-05-10 | 2019-06-17 |
Known software with vulnerabilities from Custom Field Suite Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Custom Field Suite Project | Custom Field Suite | 2.5.10 |