Podsfoundation maintains the Pods product, a focused platform-layer component that, despite limited volume, occupies a prominent role in certain deployment ecosystems. Its vulnerability profile centers on application-layer input handling and command safety, with recurring weaknesses including cross-site scripting, SQL injection, command injection, and cross-site request forgery that reflect exposure in web-facing and data-processing surfaces. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Podsfoundation over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23790HIGH Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= 2.9.10.2 versions. | May 3, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-1446CRITICAL The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | Mar 23, 2025 | 9.8 | 26 | NO | NO |
CVE-2023-6999HIGH The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the excepti | Apr 9, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-6967HIGH The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7 | Apr 9, 2024 | 8.8 | 22 | NO | NO |
CVE-2021-24339MEDIUM The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Me | Jun 21, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-24338MEDIUM The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Si | Jun 21, 2021 | 5.4 | 20 | NO | NO |
CVE-2024-11849MEDIUM The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scrip | Jan 6, 2025 | 6.1 | 19 | NO | NO |
CVE-2014-7957MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentication of administrators for req | Jan 15, 2015 | 6.8 | 18 | NO | NO |
CVE-2024-9883MEDIUM The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scrip | Nov 5, 2024 | 4.8 | 16 | NO | NO |
CVE-2023-6965MEDIUM The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, | Apr 9, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Podsfoundation.
Media articles that mention a CVE ID that affects a product developed by Podsfoundation — matched by CVE ID, not by vendor name.