Fetchdesigns operates a focused web-based product, Sign-Up Sheets, where the recurring vulnerability pattern centers on web-application input-handling and state-management weaknesses: cross-site scripting, cross-site request forgery, and improper formula neutralization in exported data. These are characteristic risks for form-collection and spreadsheet-export functionality, where user input flows directly into generated web pages and downloadable files. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fetchdesigns over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-49393CRITICAL Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Object Injection.This issue affects Sign-up Sheets: from n/a through <= 2.3.2. | Nov 6, 2025 | 9.8 | 29 | NO | NO |
CVE-2021-24441HIGH The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue | Jul 12, 2021 | 8.0 | 25 | NO | NO |
CVE-2023-39165HIGH Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets plugin <= 2.2.8 versions. | Oct 3, 2023 | 8.8 | 23 | NO | NO |
CVE-2024-6020MEDIUM The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, w | Sep 4, 2024 | 6.1 | 19 | NO | NO |
CVE-2025-26996MEDIUM Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Code Injection.This issue affects Sign-up Sheets: from | Apr 15, 2025 | 6.5 | 18 | NO | NO |
CVE-2021-24440MEDIUM The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, | Jul 12, 2021 | 4.8 | 18 | NO | NO |
CVE-2025-49391MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Cross Site Request Forgery.This issue affects Sign-up Sheets: from n/a through | Aug 20, 2025 | 4.3 | 17 | NO | NO |
CVE-2024-39654MEDIUM Missing Authorization vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.12. | Nov 1, 2024 | 5.3 | 16 | NO | NO |
CVE-2024-31303MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.11.1. | Apr 12, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fetchdesigns.
Media articles that mention a CVE ID that affects a product developed by Fetchdesigns — matched by CVE ID, not by vendor name.