cmb2 vulnerabilities
CVEs whose affected-version data names the cmb2 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-97270Medium· 6.5Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions.
Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions.
▾ SunlitJustin Sternberg · cmb2via NVD
CVE-2026-80338Medium· 6.8The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break co…
The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break co…
▾ SunlitEPSS 0.18%via NVD