Useplunk's vulnerability footprint centers on its Plunk product, a web-facing application where disclosures cluster around input-handling and request-processing weaknesses including CRLF injection, cross-site scripting, and server-side request forgery. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Useplunk over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32096HIGH Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook handler. An unauthenti | Mar 11, 2026 | 8.6 | 28 | NO | NO |
CVE-2026-34975MEDIUM Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability was discovered in SESService.ts, where user-supplied values fo | Apr 6, 2026 | 4.3 | 20 | NO | NO |
CVE-2026-32095MEDIUM Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.1, Plunk's image upload endpoint accepted SVG files, which browsers treat as active documents capable o | Mar 11, 2026 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Useplunk.
Media articles that mention a CVE ID that affects a product developed by Useplunk — matched by CVE ID, not by vendor name.