Plausible Tracking Project maintains a web analytics platform focused on privacy-preserving visitor tracking, with its vulnerability surface centered on the core tracking product. The durable signal is rooted in the application's role as a web-facing service, with observed weaknesses clustering around input-neutralization and cross-site scripting risks inherent to analytics data collection and rendering. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plausible Tracking Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-10927MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Plausible tracking allows Cross-Site Scripting (XSS).This issue affects | Oct 30, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plausible Tracking Project.
Media articles that mention a CVE ID that affects a product developed by Plausible Tracking Project — matched by CVE ID, not by vendor name.