Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Infility Global — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Infility Global, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation report for Infility Global, focusing on common software weaknesses and associated security tags. It collects data on identified vulnerabilities affecting Infility Global products, covering incidents reported from January 2018 through December 2023. Here, you can track vendor advisories to stay informed about specific patches and mitigation strategies, understand the nature and impact of a particular weakness class by analyzing its recurrence and severity scores, and look up a product's complete vulnerability history to assess its overall security posture over time. This resource is designed to help security professionals, developers, and risk managers quickly grasp the landscape of known issues without sifting through fragmented sources. By centralizing this information, the page aims to reduce the cognitive load associated with threat intelligence gathering and enable more efficient decision-making during incident response or product evaluation phases. The data is sourced from publicly available advisories, CVE entries, and vendor security bulletins, ensuring a comprehensive view of the threat surface. Users are encouraged to use the filtering tools to narrow down results by severity, version, or specific weakness type, allowing for targeted analysis. This approach supports proactive risk management by highlighting trends and repeated failure points, thereby aiding in the prioritization of security improvements and the validation of existing controls against known exploitation patterns.

Vendor: infility

CVE ID Title CVSS Severity Published
CVE-2026-10734 Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via /cf7_record Log Endpoint CWE-79 7.2 High 2026-08-16
CVE-2026-7842 Infility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter - - 2026-06-23
CVE-2026-8163 Infility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter - - 2026-06-23
CVE-2026-8685 Infility Global <= 2.15.16 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter CWE-89 6.5 Medium 2026-05-20
CVE-2025-15268 Infility Global <= 2.14.46 - Unauthenticated SQL Injection via Predictable API Key and IP Whitelist Bypass CWE-89 7.5 High 2026-02-04
CVE-2025-68864 WordPress Infility Global plugin <= 2.15.11 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-01-22
CVE-2025-68865 WordPress Infility Global plugin <= 2.15.06 - SQL Injection vulnerability CWE-89 9.3 Critical 2026-01-05
CVE-2025-12968 Infility Global <= 2.14.42 - Authenticated (Subscriber+) Arbitrary File Upload CWE-434 8.8 High 2025-12-12
CVE-2025-47650 WordPress Infility Global <= 2.15.06 - Arbitrary File Download vulnerability CWE-22 6.5 Medium 2025-08-20
CVE-2025-47652 WordPress Infility Global plugin <= 2.13.4 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2025-07-16
CVE-2025-52774 WordPress Infility Global plugin <= 2.15.06 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2025-06-27
CVE-2025-47651 WordPress Infility Global plugin <= 2.15.06 - SQL Injection vulnerability CWE-89 8.5 High 2025-06-09
CVE-2024-12723 Infility Global <= 2.9.8 - Reflected XSS 6.1 - 2025-01-28
CVE-2024-11496 Infility Global <= 2.9.8 - Authenticated (Subscriber+) Missing Authorization to Plugin Options Update CWE-862 6.5 Medium 2025-01-07
CVE-2024-12290 Infility Global <= 2.9.8 - Reflected Cross-Site Scripting via set_type Parameter CWE-79 6.1 Medium 2025-01-07

All 15 known CVE vulnerabilities affecting Infility Global with full Chinese analysis, references, and POCs where available.