POEditor is a web-based localization and translation management platform whose vulnerability profile centers on its core application and recurs through web-layer input-handling issues, specifically cross-site scripting and cross-site request forgery. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Poeditor over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32091HIGH Cross-Site Request Forgery (CSRF) vulnerability in POEditor plugin <= 0.9.4 versions. | Oct 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2025-49237HIGH Cross-Site Request Forgery (CSRF) vulnerability in POEditor POEditor poeditor allows Path Traversal.This issue affects POEditor: from n/a through <= 0.9.10. | Jun 6, 2025 | 7.4 | 21 | NO | NO |
CVE-2024-32453MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POEditor allows Stored XSS.This issue affects POEditor: from n/a through 0.9.8 | Apr 15, 2024 | 4.8 | 16 | NO | NO |
CVE-2023-4209MEDIUM The POEditor WordPress plugin before 0.9.8 does not have CSRF checks in various places, which could allow attackers to make logged in admins perform unwanted actions, such as reset | Aug 30, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Poeditor.
Media articles that mention a CVE ID that affects a product developed by Poeditor — matched by CVE ID, not by vendor name.