Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xnau

First CVE: Jun 4, 2014Active for: 12 yearsTotal CVEs: 7

Xnau maintains a focused product portfolio centered on the Participants Database plugin, a web-based data management tool that handles user input and authorization. The vendor's vulnerability profile recurs through web-application attack surfaces: cross-site request forgery, SQL injection, cross-site scripting, and missing authorization checks are the durable patterns across its disclosures, reflecting the input-validation and access-control demands of a user-facing database application. Public exploit tooling has frequently accompanied vulnerabilities in this product line; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xnau over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 4, 2014
12 years ago
Most Recent CVE
Jul 24, 2026
0 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-3961HIGH
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via th
Jun 4, 20147.537NOYES
CVE-2017-14126MEDIUM
The Participants Database plugin before 1.7.5.10 for WordPress has XSS.
Sep 4, 20176.130NOYES
CVE-2023-48751HIGH
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database allows Accessing Functionality Not Properly Constraine
Dec 19, 20238.824NONO
CVE-2023-31235HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.9 versions.
Nov 9, 20238.824NONO
CVE-2020-8596HIGH
participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_
Feb 11, 20207.524NONO
CVE-2022-47612MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.5 leads to list column update.
Feb 28, 20234.317NONO
CVE-2026-11354MEDIUM
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it p
Jul 24, 20265.3—NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
43%
57%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (85.7%)
Unknown1 (14.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (71.4%)
High1 (14.3%)
Unknown1 (14.3%)
User Interaction
None2 (28.6%)
Unknown1 (14.3%)
Required4 (57.1%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None5 (71.4%)
Unknown1 (14.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
28.6% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xnau.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xnau — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xnau's Products

View all 3 CNAs →

Top CWEs