| CVE-2026-25417 | WordPress ProfileGrid plugin <= 5.9.8.1 - Cross Site Scripting (XSS) vulnerability | Metagauss | ProfileGrid | Medium | 6.5 | 2026-03-25 16:14:49 | Deep Dive |
| CVE-2026-2494 | ProfileGrid <= 5.9.8.2 - Cross-Site Request Forgery to Group Membership Request Approval/Denial | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 4.3 | 2026-03-07 01:21:22 | Deep Dive |
| CVE-2026-2488 | ProfileGrid <= 5.9.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 4.3 | 2026-03-07 01:21:22 | Deep Dive |
| CVE-2026-1271 | ProfileGrid <= 5.9.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 5.3 | 2026-02-05 09:13:45 | Deep Dive |
| CVE-2025-13416 | ProfileGrid – User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 4.3 | 2026-02-05 08:25:44 | Deep Dive |
| CVE-2025-4957 | WordPress ProfileGrid plugin <= 5.9.5.7 - Reflected Cross Site Scripting (XSS) vulnerability | Metagauss | ProfileGrid | High | 7.1 | 2025-09-26 08:31:15 | Deep Dive |
| CVE-2025-49033 | WordPress ProfileGrid plugin <= 5.9.5.3 - SQL Injection vulnerability | Metagauss | ProfileGrid | High | 8.5 | 2025-08-14 10:34:23 | Deep Dive |
| CVE-2025-49876 | WordPress ProfileGrid plugin <= 5.9.5.2 - SQL Injection vulnerability | Metagauss | ProfileGrid | High | 8.5 | 2025-07-16 11:27:59 | Deep Dive |
| CVE-2025-6977 | ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 6.1 | 2025-07-16 04:24:03 | Deep Dive |
| CVE-2025-52719 | WordPress ProfileGrid plugin <= 5.9.5.2 - Full Path Disclosure (FPD) Vulnerability | Metagauss | ProfileGrid | Medium | 4.3 | 2025-06-20 15:03:37 | Deep Dive |
| CVE-2025-49877 | WordPress ProfileGrid plugin <= 5.9.5.2 - Server Side Request Forgery (SSRF) Vulnerability | Metagauss | ProfileGrid | Medium | 4.9 | 2025-06-17 15:01:15 | Deep Dive |
| CVE-2025-47478 | WordPress ProfileGrid plugin <= 5.9.5.0 - SQL Injection Vulnerability | Metagauss | ProfileGrid | High | 8.5 | 2025-05-23 12:43:35 | Deep Dive |
| CVE-2025-48079 | WordPress ProfileGrid plugin <= 5.9.5.1 - Broken Access Control Vulnerability | Metagauss | ProfileGrid | Medium | 4.3 | 2025-05-16 15:45:05 | Deep Dive |
| CVE-2025-39586 | WordPress ProfileGrid plugin <= 5.9.4.8 - SQL Injection Vulnerability | Metagauss | ProfileGrid | High | 8.5 | 2025-04-17 15:46:45 | Deep Dive |
| CVE-2025-0724 | ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object Injection | metagauss | ProfileGrid – User Profiles, Groups and Communities | High | 8.8 | 2025-03-22 04:22:06 | Deep Dive |
| CVE-2025-1408 | ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.4 - Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 4.3 | 2025-03-22 04:22:06 | Deep Dive |
| CVE-2025-0723 | ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.7 - Authenticated (Subscriber+) SQL Injection | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 6.5 | 2025-03-22 04:22:05 | Deep Dive |
| CVE-2025-26999 | WordPress ProfileGrid Plugin <= 5.9.4.3 - PHP Object Injection vulnerability | Metagauss | ProfileGrid | High | 8.8 | 2025-03-03 13:30:01 | Deep Dive |
| CVE-2024-13740 | ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 4.3 | 2025-02-18 02:06:01 | Deep Dive |
| CVE-2024-13741 | ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Authenticated (Subscriber+) Limited Server-Side Request Forgery | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 5.4 | 2025-02-18 01:44:01 | Deep Dive |