Vendor
Cozmoslabs vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 17 vulnerabilities in Cozmoslabs: 1 in the last 7 days and 14 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-95866, was published on 25 September 2026. 3 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 14
- Critical, all time
- 1
- Exploited in the wild
- 0
About Cozmoslabs
A software company specializing in WordPress plugins and tools for developers and site owners.
Cozmoslabs technologies
Latest Cozmoslabs vulnerabilities
- CVE-2026-95866: Profile Builder stored XSS in avatar fieldhighCVSS 7.2EPSS 0.3%
- CVE-2026-75965: Profile Builder stored XSS via date shortcode attributemediumCVSS 6.4EPSS 0.3%
- CVE-2026-82607: Cozmoslabs Profile Builder unrestricted file upload in avatar handlerhighCVSS 7.3EPSS 0.5%
- CVE-2026-76548: User Profile Builder authentication bypass in file uploadhighCVSS 8.2EPSS 0.3%
- CVE-2026-76547: User Profile Builder PHP Object Injection in import/exportmediumCVSS 6.6EPSS 0.4%
- CVE-2026-76546: User Profile Builder stored XSS in format date shortcodemediumCVSS 6.8EPSS 0.4%
- CVE-2026-78267: TranslatePress privilege escalation in multilingual plugincriticalCVSS 9.8EPSS 0.5%
- CVE-2026-66701: WordPress Profile Builder broken access controlmediumCVSS 5.3EPSS 0.3%
- CVE-2026-15368: Cozmoslabs User Profile Builder account takeover via auto-login after registrationinfoCVSS 8.1
- CVE-2026-14849: Cozmoslabs Paid Member Subscriptions Information Exposure in Export FilesinfoCVSS 3.7
- CVE-2026-14847: Cozmoslabs Paid Member Subscriptions IDOR in payment refund modalinfoCVSS 4.3
- CVE-2026-59539: Cozmoslabs Paid Member Subscriptions IDOR in Subscriber componenthighCVSS 7.5
- CVE-2026-61971: Cozmoslabs User Profile Picture IDOR in metronet-profile-picturelowCVSS 2.7
- CVE-2026-57348: Cozmoslabs Paid Member Subscriptions SSRF in WordPress pluginhighCVSS 7.2
- CVE-2026-42385: Cozmoslabs Profile Builder Pro unauthenticated XSShighCVSS 7.1
- CVE-2026-39514: Cozmoslabs Paid Member Subscriptions unauthenticated XSShighCVSS 7.1
- CVE-2026-3139: Cozmoslabs User Profile Builder IDOR in wppb_save_avatar_valuemediumCVSS 4.3EPSS 0.2%
Most severe Cozmoslabs vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-78267: TranslatePress privilege escalation in multilingual plugincriticalCVSS 9.8EPSS 0.5%
- CVE-2026-76548: User Profile Builder authentication bypass in file uploadhighCVSS 8.2EPSS 0.3%
- CVE-2026-59539: Cozmoslabs Paid Member Subscriptions IDOR in Subscriber componenthighCVSS 7.5
- CVE-2026-82607: Cozmoslabs Profile Builder unrestricted file upload in avatar handlerhighCVSS 7.3EPSS 0.5%
- CVE-2026-95866: Profile Builder stored XSS in avatar fieldhighCVSS 7.2EPSS 0.3%
- CVE-2026-57348: Cozmoslabs Paid Member Subscriptions SSRF in WordPress pluginhighCVSS 7.2
- CVE-2026-42385: Cozmoslabs Profile Builder Pro unauthenticated XSShighCVSS 7.1
- CVE-2026-39514: Cozmoslabs Paid Member Subscriptions unauthenticated XSShighCVSS 7.1
- CVE-2026-76546: User Profile Builder stored XSS in format date shortcodemediumCVSS 6.8EPSS 0.4%
- CVE-2026-76547: User Profile Builder PHP Object Injection in import/exportmediumCVSS 6.6EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 4 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 4 | 1 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/cozmoslabs.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Cozmoslabs vulnerabilities", https://junglewise.ai/threats/vendors/cozmoslabs, 26 September 2026.