Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Podlove Podcast Publisher — Vulnerabilities & Security Advisories 26

All 26 CVE vulnerabilities found in Podlove Podcast Publisher, with AI-generated Chinese analysis, references, and POCs.

This page aggregates documented security vulnerabilities associated with the Podlove Podcast Publisher, a podcast hosting and management tool, categorized by their specific weakness types and affected components. It collects a historical record of identified flaws, ranging from early 2015 to recent years, covering both minor configuration issues and critical security defects reported across the software's lifecycle. Readers can use this index to track the vendor's advisory history, understand the recurring weakness classes affecting this product, and review the complete vulnerability timeline without searching individual database entries. The collection includes data points on affected versions, severity ratings, and fix details, providing a consolidated view for risk assessment and patch management.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-93775 Podlove Podcast Publisher <= 4.5.6 - Unauthenticated Stored Cross-Site Scripting via Auphonic Webhook CWE-79 7.2 High 2026-10-10
CVE-2026-75966 Podlove Podcast Publisher <= 4.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter CWE-79 6.4 Medium 2026-09-09
CVE-2026-66615 WordPress Podlove Podcast Publisher plugin <= 4.5.4 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-08-20
CVE-2026-16099 Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter CWE-502 8.8 High 2026-08-16
CVE-2026-13729 Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF - - 2026-08-01
CVE-2026-13001 Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter CWE-20 9.8 Critical 2026-07-14
CVE-2026-32448 WordPress Podlove Podcast Publisher plugin <= 4.3.3 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-03-13
CVE-2025-10147 Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload CWE-434 9.8 Critical 2025-09-23
CVE-2025-58204 WordPress Podlove Podcast Publisher Plugin <= 4.2.5 - Open Redirection Vulnerability CWE-601 4.7 Medium 2025-08-27
CVE-2024-13730 Podlove Podcast Publisher < 4.2.1 - Admin+ Stored XSS 4.8AI Medium AI 2025-05-15
CVE-2024-13729 Podlove Podcast Publisher < 4.1.24 - Admin+ Stored XSS 4.8AI Medium AI 2025-05-15
CVE-2025-1383 Podlove Podcast Publisher <= 4.2.2 - Cross-Site Request Forgery via ajax_transcript_delete Function CWE-352 4.3 Medium 2025-03-06
CVE-2025-0554 Podlove Podcast Publisher <= 4.1.25 - Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name CWE-79 4.4 Medium 2025-01-18
CVE-2024-52393 WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerability CWE-82 9.1 Critical 2024-11-14
CVE-2024-43984 WordPress Podlove Podcast Publisher plugin <= 4.1.13 - CSRF to Remote Code Execution (RCE) vulnerability CWE-352 9.6 Critical 2024-10-31
CVE-2024-43983 WordPress Podlove Podcast Publisher plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-09-17
CVE-2024-32143 WordPress Podlove Podcast Publisher plugin <= 4.1.0 - Broken Access Control vulnerability CWE-862 4.3 Medium 2024-06-11
CVE-2024-32712 WordPress Podlove Podcast Publisher plugin <= 4.0.14 - Broken Access Control vulnerability CWE-862 7.5 High 2024-05-09
CVE-2024-32812 WordPress Podlove Podcast Publisher plugin <= 4.0.11 - Server Side Request Forgery (SSRF) vulnerability CWE-918 5.4 Medium 2024-04-24
CVE-2024-32139 WordPress Podlove Podcast Publisher plugin <= 4.0.12 - SQL Injection vulnerability CWE-89 8.5 High 2024-04-15
CVE-2024-29915 WordPress Podlove Podcast Publisher plugin <= 4.0.9 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-03-27
CVE-2024-1110 Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Settings Import CWE-862 5.3 Medium 2024-02-07
CVE-2024-1109 Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Unauthenticated Data Export CWE-862 5.3 Medium 2024-02-07
CVE-2023-25472 WordPress Podlove Podcast Publisher Plugin <= 3.8.3 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium 2023-05-23
CVE-2023-25046 WordPress Podlove Podcast Publisher Plugin <= 3.8.2 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium 2023-04-07
CVE-2021-24666 Podlove Podcast Publisher < 3.5.6 - Unauthenticated SQL Injection CWE-89 9.8 - 2021-09-27

All 26 known CVE vulnerabilities affecting Podlove Podcast Publisher with full Chinese analysis, references, and POCs where available.