Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Verbb

First CVE: May 25, 2020Active for: 6 yearsTotal CVEs: 10
8.1
VTI Score
Low

Verbb maintains a modestly represented portfolio of web-based plugins and utilities, including commenting systems, form builders, and image-processing components that extend widely used content-management platforms. Its vulnerabilities concentrate in application-layer input and output handling, with recurring weakness classes including cross-site scripting, template-injection variants, CSRF, and open-redirect flaws that are characteristic of web-facing extensions and reflect the complexity of safely rendering and processing user-supplied content. A meaningful share of the vendor's disclosures reach serious severity, warranting prompt attention to its advisories; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Verbb over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 25, 2020
6 years ago
Most Recent CVE
Apr 11, 2025
469 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-13485CRITICAL
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
May 25, 20209.123NONO
CVE-2020-13868MEDIUM
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
Jun 5, 20206.522NONO
CVE-2020-13458HIGH
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.
May 25, 20208.822NONO
CVE-2025-32427MEDIUM
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or handle contained malicious content, the output wasn't corre
Apr 11, 20255.418NONO
CVE-2025-32426MEDIUM
Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rend
Apr 11, 20255.418NONO
CVE-2020-13486MEDIUM
The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
May 25, 20206.117NONO
CVE-2024-35191MEDIUM
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might b
May 20, 20244.415NONO
CVE-2020-13870MEDIUM
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.
Jun 5, 20205.415NONO
CVE-2020-13869MEDIUM
An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name.
Jun 5, 20205.415NONO
CVE-2020-13459MEDIUM
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.
May 25, 20205.415NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
80%
10%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (20.0%)
Unknown0 (0.0%)
Required8 (80.0%)
Privileges Required
Low5 (50.0%)
High1 (10.0%)
None4 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Verbb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Verbb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Verbb's Products

View all 2 CNAs →

Top CWEs