Xnau maintains a focused product portfolio centered on the Participants Database plugin, a web-based data management tool that handles user input and authorization. The vendor's vulnerability profile recurs through web-application attack surfaces: cross-site request forgery, SQL injection, cross-site scripting, and missing authorization checks are the durable patterns across its disclosures, reflecting the input-validation and access-control demands of a user-facing database application. Public exploit tooling has frequently accompanied vulnerabilities in this product line; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xnau over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-3961HIGH SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via th | Jun 4, 2014 | 7.5 | 37 | NO | YES |
CVE-2017-14126MEDIUM The Participants Database plugin before 1.7.5.10 for WordPress has XSS. | Sep 4, 2017 | 6.1 | 30 | NO | YES |
CVE-2023-48751HIGH Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database allows Accessing Functionality Not Properly Constraine | Dec 19, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-31235HIGH Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.9 versions. | Nov 9, 2023 | 8.8 | 24 | NO | NO |
CVE-2020-8596HIGH participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_ | Feb 11, 2020 | 7.5 | 24 | NO | NO |
CVE-2022-47612MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.5 leads to list column update. | Feb 28, 2023 | 4.3 | 17 | NO | NO |
CVE-2026-11354MEDIUM The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it p | Jul 24, 2026 | 5.3 | — | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xnau.
Media articles that mention a CVE ID that affects a product developed by Xnau — matched by CVE ID, not by vendor name.