Gumroad is an online creator-commerce platform that facilitates direct sales and content distribution, with its vulnerability profile centered narrowly on its web application. The recurring exposure involves cross-site scripting weaknesses in web page generation, a class typical of customer-facing platforms handling user-supplied content and form inputs. Current vulnerability counts and severity figures are shown in the live-stats panel alongside this summary.
The number and severity of CVEs published that impact products developed by Gumroad over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45059MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Gumroad plugin <= 3.1.0 versions. | Oct 18, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gumroad.
Media articles that mention a CVE ID that affects a product developed by Gumroad — matched by CVE ID, not by vendor name.