VulnSea

mageplaza has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.5 (high).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
3 prev 0

Products

  • gdpr 1
  • magefan_blog 1
  • mageplaza_blog 1
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

mageplaza vulnerabilities

CVEs affecting mageplaza, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-79324High· 7.5
2w ago

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresse…

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresse…

Twilightmageplaza · gdprEPSS 0.32%via NVD
CVE-2026-79323High· 7.5
2w ago

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal cus…

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal cus…

Twilightmageplaza · magefan_blogEPSS 0.33%via NVD
CVE-2026-79322High· 8.6
2w ago

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents v…

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents v…

Twilightmageplaza · mageplaza_blogEPSS 0.28%via NVD
mageplaza vulnerabilities (CVEs) · VulnSea