Postsnippets develops a web-based code-snippet management product whose vulnerability surface concentrates on client-side input-handling issues, specifically cross-site request forgery and cross-site scripting flaws that are characteristic of web applications handling user-supplied content. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Postsnippets over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56049HIGH Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. | Jun 25, 2026 | 8.5 | 36 | NO | NO |
CVE-2021-25010CRITICAL The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, i | Feb 28, 2022 | 9.6 | 29 | NO | NO |
CVE-2023-25459MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Postsnippets Post Snippets plugin <= 4.0.2 versions. | Aug 8, 2023 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Postsnippets.
Media articles that mention a CVE ID that affects a product developed by Postsnippets — matched by CVE ID, not by vendor name.