Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Metagauss

First CVE: Sep 3, 2019Active for: 7 yearsTotal CVEs: 128
39.7
VTI Score
Medium

Metagauss develops a focused suite of WordPress plugins and themes for community engagement, user registration, and event management, products that sit within millions of WordPress deployments despite limited vendor breadth. Its vulnerability profile concentrates in access-control and input-handling weaknesses endemic to web applications—missing authorization, cross-site scripting, CSRF, SQL injection, and authorization-bypass flaws—reflecting the intersection of plugin architecture, user-facing forms, and database interaction inherent to these tools. The vendor's disclosures span a meaningful share of serious-severity outcomes, and the recurrence of these foundational web-layer weakness classes across multiple products underscores the sustained importance of defensive coding practices in extensible platform ecosystems. Defenders should review any Metagauss plugins or themes in active use and prioritize patches addressing authorization and injection-class flaws; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
128
Total CVEs
More Total CVEs than 99% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Metagauss over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 3, 2019
6 years ago
Most Recent CVE
Jul 13, 2026
11 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (128 CVEs).

128 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24862HIGH
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in bat
Jan 10, 20227.286NOYES
CVE-2021-4073HIGH
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site du
Dec 14, 20218.143NOYES
CVE-2024-30491HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.
Mar 29, 20248.840NONO
CVE-2024-30490CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.
Mar 29, 20249.840NOYES
CVE-2026-57759HIGH
Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
Jul 2, 20268.837NONO
CVE-2026-49764CRITICAL
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
Jun 15, 20269.835NONO
CVE-2026-57697HIGH
Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitat
Jul 13, 20267.533NONO
CVE-2022-3578MEDIUM
The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Nov 14, 20226.132NOYES
CVE-2026-24378CRITICAL
Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through
Mar 25, 20269.831NONO
CVE-2026-24380HIGH
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue
Jan 22, 20268.831NONO
View all 128 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products128 CVEs
53%
41%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network128 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low125 (97.7%)
High3 (2.3%)
Unknown0 (0.0%)
User Interaction
None87 (68.0%)
Unknown0 (0.0%)
Required41 (32.0%)
Privileges Required
Low60 (46.9%)
High9 (7.0%)
None59 (46.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (128 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.8% of CVEs· 97th percentile
Nuclei
4 CVEs
3.1% of CVEs· 95th percentile
ExploitDB
1 CVE
0.8% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Metagauss.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Metagauss — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Metagauss's Products

View all 4 CNAs →

Top CWEs