Cozmoslabs Profile Builder Pro vulnerabilities

4 known vulnerabilities affecting cozmoslabs/profile_builder_pro.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-27413CRITICALCVSS 9.3≥ n/a, < 3.14.02026-03-19
CVE-2026-27413 [CRITICAL] CWE-89 CVE-2026-27413: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0.
cvelistv5nvd
CVE-2024-22140HIGHCVSS 8.8≥ n/a, ≤ 3.10.02024-01-31
CVE-2024-22140 [HIGH] CWE-352 CVE-2024-22140: Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.
cvelistv5nvd
CVE-2024-22141HIGHCVSS 7.5≥ n/a, ≤ 3.10.02024-01-24
CVE-2024-22141 [HIGH] CWE-200 CVE-2024-22141: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Build Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.
cvelistv5nvd
CVE-2024-22142MEDIUMCVSS 6.1≥ n/a, ≤ 3.10.02024-01-13
CVE-2024-22142 [MEDIUM] CWE-79 CVE-2024-22142: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Profile Builder Pro allows Reflected XSS.This issue affects Profile Builder Pro: from n/a through 3.10.0.
cvelistv5nvd