Pie Register

Vendor:

First CVE: Jul 29, 2013 · Active for 12 years

14
Total CVEs
More Total CVEs than 92% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pie Register over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2013
12 years ago
Most Recent CVE
Feb 21, 2025
521 days ago

CVE Severity & Scoring

Pie Register14 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (71.4%)
Unknown4 (28.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (64.3%)
High1 (7.1%)
Unknown4 (28.6%)
User Interaction
None6 (42.9%)
Unknown4 (28.6%)
Required4 (28.6%)
Privileges Required
Low1 (7.1%)
High0 (0.0%)
None9 (64.3%)
Unknown4 (28.6%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.
Jun 17, 20189.844NOYES
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data b
Nov 8, 20219.843NOYES
The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability
Feb 27, 20235.440NOYES
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login imple
Nov 8, 20218.140NOYES
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
Aug 27, 20199.831NONO
The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET paramete
Apr 22, 20216.129NOYES
Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web scr
Oct 16, 20154.329NOYES
Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.
Mar 17, 20249.827NONO
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by u
Jan 23, 20155.025NOYES
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to de
Dec 19, 20226.523NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
35.7% of CVEs· 98th percentile
ExploitDB
3 CVEs
21.4% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Pie Register

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0.1516.11.6%00
1.2.9112.66.2%01
1.2.912.66.2%01
1.2.812.66.2%01
1.2.712.66.2%01
1.2.612.66.2%01
1.2.412.66.2%01
1.2.312.66.2%01
1.2.212.66.2%01
1.2.112.66.2%01
1.2.012.66.2%01
1.1.912.66.2%01
1.1.812.66.2%01
1.1.712.66.2%01
1.1.612.66.2%01
1.1.512.66.2%01
1.1.312.66.2%01
1.1.212.66.2%01
1.1.112.66.2%01
1.0.112.66.2%01