Pricing
Case studies
Login
Start trial
Groundhogg
Adrian Tobey
Developer
4.4.1
Latest version
2,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
17 patched
7 Mitigation rules
Cross Site Scripting (XSS) vulnerability
<= 4.2.6
23/11/2025
Authenticated (Admin+) SQL Injection vulnerability
<= 4.2.6.1
20/11/2025
PHP Object Injection vulnerability
<= 4.2.2
05/08/2025
Arbitrary File Upload vulnerability
<= 4.2.1
04/07/2025
Authenticated (Administrator+) Arbitrary File Deletion vulnerability
<= 4.1.1.2
09/05/2025
Authenticated (Administrator+) Stored Cross-Site Scripting via label Parameter vulnerability
<= 3.7.4.1
31/03/2025
Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Function vulnerability
<= 3.7.3.5
13/01/2025
Reflected Cross Site Scripting (XSS) vulnerability
<= 3.7.3.3
03/01/2025
Reflected Cross Site Scripting (XSS) vulnerability
<= 3.4.2.3
27/06/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 3.4.2.3
21/06/2024
Cross Site Scripting (XSS) vulnerability
<= 2.7.11.10
25/10/2023
SQL Injection vulnerability
<= 2.7.11
30/05/2023
Cross Site Request Forgery (CSRF)
<= 2.7.11
30/05/2023
Cross-Site Request Forgery to Privilege Escalation vulnerability
<= 2.7.9.8
22/05/2023
Multiple Missing Authorization vulnerability
<= 2.7.9.8
22/05/2023
Auth. Stored Cross-Site Scripting (XSS) vulnerability
<= 2.7.9.8
19/05/2023
Admin+ SQLi vulnerability
< 2.7.9.4
11/04/2023