Keap's vulnerability footprint is concentrated in its cloud-based opt-in forms and landing-page products, which serve as customer-acquisition and lead-capture tools for small businesses and marketing automation workflows. The observed weakness classes center on web-application input handling and request validation, including cross-site scripting, cross-site request forgery, and path-traversal conditions that are characteristic of form-processing and content-delivery surfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keap over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13725CRITICAL The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter. This makes it possi | Feb 18, 2025 | 9.8 | 28 | NO | NO |
CVE-2023-44241HIGH Cross-Site Request Forgery (CSRF) vulnerability in Keap Keap Landing Pages plugin <= 1.4.2 versions. | Oct 10, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-52192MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keap Keap Official Opt-in Forms allows Stored XSS.This issue affects Keap Offi | Feb 1, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-6941MEDIUM The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform St | Jan 15, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keap.
Media articles that mention a CVE ID that affects a product developed by Keap — matched by CVE ID, not by vendor name.