Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Custom Field Template — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Custom Field Template, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with the Custom Field Template product developed by Atlassian. It aggregates security advisory data and technical details regarding known weaknesses within this specific software component, providing a centralized resource for understanding its risk landscape. The content covers vulnerabilities identified and reported over the past several years, ensuring that users have access to both historical context and recent security updates affecting the product. By reviewing this collection, security professionals and developers can effectively track vendor advisories from Atlassian, gaining insight into how the company addresses and patches specific issues as they arise. Furthermore, this page allows users to deeply understand the nature of the weakness classes present in Custom Field Template, helping them prioritize remediation efforts based on severity and exploitability. Visitors can also look up the product’s comprehensive vulnerability history, observing trends and patterns in reported security flaws over time. This historical perspective is crucial for assessing the long-term security posture of the software and making informed decisions about upgrade paths or mitigation strategies. The information provided is intended to support technical analysis and compliance requirements without offering promotional commentary or speculative insights. All entries are based on verified public disclosures and vendor communications, ensuring accuracy and reliability for stakeholders managing this product in their environments.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-12995 Custom Field Template <= 2.7.8 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Media File Deletion via 'file_field' Parameter CWE-639 4.3 Medium 2026-09-22
CVE-2026-9855 Custom Field Template <= 2.7.8 - Authenticated (Contributor+) SQL Injection via 'post_ID' Parameter CWE-89 6.5 Medium 2026-09-19
CVE-2026-57687 WordPress Custom Field Template plugin <= 2.7.8 - SQL Injection vulnerability CWE-89 8.5 High 2026-07-02
CVE-2025-68607 WordPress Custom Field Template plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-12-29
CVE-2025-63058 WordPress Custom Field Template plugin <= 2.7.6 - Sensitive Data Exposure vulnerability CWE-497 4.3 Medium 2025-12-09
CVE-2024-44062 WordPress Custom Field Template plugin <= 2.6.5 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-09-15
CVE-2024-0653 Custom Field Template <= 2.6.1 - Authenticated (Admin+) Stored Cross-Site Scritping CWE-79 4.4 Medium 2024-06-11
CVE-2023-6748 Custom Field Template <= 2.6.1 - Authenticated(Contributor+) Information Exposure CWE-862 4.3 Medium 2024-06-11
CVE-2024-0627 Custom Field Template <= 2.6.1 - Authenticated(Constibutor+) Stored Cross-Site Scripting via Custom Field Name CWE-79 6.4 Medium 2024-06-11
CVE-2023-6745 Custom Field Template <= 2.6.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode CWE-79 6.4 Medium 2024-06-11
CVE-2024-25919 WordPress Custom Field Template plugin <= 2.6 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-03-15
CVE-2023-38392 WordPress Custom Field Template Plugin <= 2.5.9 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High 2023-08-07
CVE-2023-22695 WordPress Custom Field Template Plugin <= 2.5.8 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium 2023-07-10
CVE-2020-36742 Custom Field Template <= 2.5.1 - Cross-Site Request Forgery Bypass CWE-352 4.3 Medium 2023-07-01
CVE-2022-4324 Custom Field Template < 2.5.8 - Admin+ PHP Object Injection 7.2 - 2023-01-02

All 15 known CVE vulnerabilities affecting Custom Field Template with full Chinese analysis, references, and POCs where available.