Verbb maintains a modestly represented portfolio of web-based plugins and utilities, including commenting systems, form builders, and image-processing components that extend widely used content-management platforms. Its vulnerabilities concentrate in application-layer input and output handling, with recurring weakness classes including cross-site scripting, template-injection variants, CSRF, and open-redirect flaws that are characteristic of web-facing extensions and reflect the complexity of safely rendering and processing user-supplied content. A meaningful share of the vendor's disclosures reach serious severity, warranting prompt attention to its advisories; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Verbb over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13485CRITICAL The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header. | May 25, 2020 | 9.1 | 23 | NO | NO |
CVE-2020-13868MEDIUM An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity. | Jun 5, 2020 | 6.5 | 22 | NO | NO |
CVE-2020-13458HIGH An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action. | May 25, 2020 | 8.8 | 22 | NO | NO |
CVE-2025-32427MEDIUM Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or handle contained malicious content, the output wasn't corre | Apr 11, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-32426MEDIUM Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rend | Apr 11, 2025 | 5.4 | 18 | NO | NO |
CVE-2020-13486MEDIUM The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection. | May 25, 2020 | 6.1 | 17 | NO | NO |
CVE-2024-35191MEDIUM Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might b | May 20, 2024 | 4.4 | 15 | NO | NO |
CVE-2020-13870MEDIUM An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name. | Jun 5, 2020 | 5.4 | 15 | NO | NO |
CVE-2020-13869MEDIUM An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name. | Jun 5, 2020 | 5.4 | 15 | NO | NO |
CVE-2020-13459MEDIUM An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action. | May 25, 2020 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Verbb.
Media articles that mention a CVE ID that affects a product developed by Verbb — matched by CVE ID, not by vendor name.