Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ProfileGrid – User Profiles, Groups and Communities — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in ProfileGrid – User Profiles, Groups and Communities, with AI-generated Chinese analysis, references, and POCs.

This page aggregates verified security vulnerabilities for the product ProfileGrid – User Profiles, Groups and Communities, a platform for user profiles, groups, and communities. The collection focuses on known defects in the product's identity management and community features, covering advisories published within the last five years. Readers can track the vendor's release patterns, understand recurring weakness classes such as broken access control or session fixation, and review the full vulnerability history of this specific software build.

Vendor: metagauss

CVE ID Title CVSS Severity Published
CVE-2026-12073 ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite CWE-639 9.8 Critical 2026-06-30
CVE-2026-4610 ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content CWE-79 6.4 Medium 2026-06-23
CVE-2026-4607 ProfileGrid <= 5.9.8.4 - Missing Authorization to Authenticated (Subscriber+) Group Settings Modification CWE-862 4.3 Medium 2026-05-13
CVE-2026-4609 ProfileGrid <= 5.9.8.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Group Joining CWE-862 7.1 High 2026-05-13
CVE-2026-4608 ProfileGrid <= 5.9.8.4 - Authenticated (Subscriber+) SQL Injection via 'rid' Parameter CWE-89 6.5 Medium 2026-05-13
CVE-2026-2488 ProfileGrid <= 5.9.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion CWE-862 4.3 Medium 2026-03-07
CVE-2026-2494 ProfileGrid <= 5.9.8.2 - Cross-Site Request Forgery to Group Membership Request Approval/Denial CWE-352 4.3 Medium 2026-03-07
CVE-2026-1271 ProfileGrid <= 5.9.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification CWE-639 5.3 Medium 2026-02-05
CVE-2025-13416 ProfileGrid – User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension CWE-862 4.3 Medium 2026-02-05
CVE-2025-6977 ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function CWE-79 6.1 Medium 2025-07-16
CVE-2025-0724 ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object Injection CWE-502 8.8 High 2025-03-22
CVE-2025-1408 ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.4 - Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management CWE-862 4.3 Medium 2025-03-22
CVE-2025-0723 ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.7 - Authenticated (Subscriber+) SQL Injection CWE-89 6.5 Medium 2025-03-22
CVE-2024-13740 ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure CWE-639 4.3 Medium 2025-02-18
CVE-2024-13741 ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Authenticated (Subscriber+) Limited Server-Side Request Forgery CWE-918 5.4 Medium 2025-02-18
CVE-2024-10900 ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Deletion CWE-862 6.5 Medium 2024-11-20
CVE-2024-8861 ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-09-26
CVE-2024-6410 ProfileGrid <= 5.8.9 - Authenticated (Subscriber+) Insecure Direct Object Reference CWE-639 4.3 Medium 2024-07-10
CVE-2024-6411 ProfileGrid – User Profiles, Groups and Communities <= 5.8.9 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation CWE-269 8.8 High 2024-07-10
CVE-2024-5453 ProfileGrid <= 5.8.6 - Missing Authorization CWE-862 4.3 Medium 2024-06-05
CVE-2024-3606 ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.8.3 - Missing Authorization CWE-862 4.3 Medium 2024-05-02
CVE-2023-3404 ProfileGrid <= 5.5.0 - Hardcoded Encryption Key CWE-321 4.9 Medium 2023-08-31
CVE-2023-3714 ProfileGrid <= 5.5.2 - Missing Authorization to Arbitrary Group Option Modification and Privilege Escalation CWE-862 7.5 High 2023-07-18
CVE-2023-3403 ProfileGrid <= 5.5.1 - Missing Authorization to User Import CWE-862 5.4 Medium 2023-07-18
CVE-2023-3713 ProfileGrid <= 5.5.1 - Authenticated (Subscriber+) Arbitrary Option Update CWE-862 8.8 High 2023-07-18

All 25 known CVE vulnerabilities affecting ProfileGrid – User Profiles, Groups and Communities with full Chinese analysis, references, and POCs where available.