Patreon's vulnerability footprint centers on a WordPress plugin and a Flutter library component, a narrow product range that nonetheless sits in creator-economy infrastructure and mobile applications. The recurring weakness classes—cross-site request forgery, cross-site scripting, deserialization flaws, SQL injection, and information exposure—reflect the input-handling and data-integrity demands of web middleware and serialization layers, and vulnerabilities here skew strongly toward critical-severity outcomes while acquiring public exploit code. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Patreon over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24227HIGH The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this att | Apr 12, 2021 | 7.5 | 35 | NO | YES |
CVE-2021-24229CRITICAL The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX | Apr 12, 2021 | 9.6 | 27 | NO | NO |
CVE-2018-20984CRITICAL The patreon-connect plugin before 1.2.2 for WordPress has Object Injection. | Aug 22, 2019 | 9.8 | 27 | NO | NO |
CVE-2021-24228CRITICAL The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked | Apr 12, 2021 | 9.6 | 26 | NO | NO |
CVE-2023-41129HIGH Cross-Site Request Forgery (CSRF) vulnerability in Patreon Patreon WordPress.This issue affects Patreon WordPress: from n/a through 1.8.6. | Nov 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-24230HIGH The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or c | Apr 12, 2021 | 8.1 | 24 | NO | NO |
CVE-2023-41387CRITICAL A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. | Sep 19, 2023 | 9.1 | 22 | NO | NO |
CVE-2021-25026MEDIUM The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting | Mar 14, 2022 | 5.5 | 21 | NO | NO |
CVE-2021-24231MEDIUM The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged administrator disconne | Apr 12, 2021 | 6.5 | 21 | NO | NO |
CVE-2025-24588MEDIUM Missing Authorization vulnerability in patreon Patreon WordPress patreon-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Patreon | Jan 24, 2025 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Patreon.
Media articles that mention a CVE ID that affects a product developed by Patreon — matched by CVE ID, not by vendor name.