Known vulnerabilities in Pods – Custom Content Types and Fields
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
18Reported vulnerabilities
9.8Highest CVSS score
3.3.9.1Latest version
100,000+Active installs
What to do now
Update Pods – Custom Content Types and Fields to 3.3.9.2 or later.
18 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-1446 | Critical | 0.4% | Before 3.2.8.2 | 3.2.8.2 |
March 23, 2025 |
| CVE-2014-7957 | Medium | 1.2% | 2.4.3 and earlier | 2.5 |
January 15, 2015 |
| CVE-2026-19598 | Critical | 2.8% | 2.8 to 2.8.23.3 (inclusive) 2.9 to 2.9.19.3 (inclusive) 3.0 to 3.0.10.3 (inclusive) 3.1 to 3.1.4.1 (inclusive) 3.2 to 3.2.8.2 (inclusive) 3.3 to 3.3.9 (inclusive) |
2.8.23.4 |
August 15, 2026 |
| CVE-2024-11849 | Medium | 0.3% | Before 3.2.8.1 | 3.2.8.1 |
January 6, 2025 |
| CVE-2021-24339 | Medium | 0.8% | Before 2.7.27 | 2.7.27 |
June 21, 2021 |
| CVE-2021-24338 | Medium | 0.8% | Before 2.7.27 | 2.7.27 |
June 21, 2021 |
| WF-e95b2bfe-8675-4932-9b37-73ad15fa228e | Critical | — | Before 2.5.1.2 | 2.5.1.2 |
March 16, 2015 |
| CVE-2023-6999 | High | 1.3% | Before 2.7.31.2 2.8 up to (but not including) 2.8.23.2 2.9 up to (but not including) 2.9.19.2 3.0.0 up to (but not including) 3.0.10.2 |
2.7.31.2 |
April 9, 2024 |
| CVE-2023-6967 | High | 0.8% | Before 2.7.31.2 2.8 up to (but not including) 2.8.23.2 2.9 up to (but not including) 2.9.19.2 3.0.0 up to (but not including) 3.0.10.2 |
2.7.31.2 |
April 9, 2024 |
| CVE-2014-7956 | Medium | 2.0% | 2.4.3 and earlier | 2.5 |
January 15, 2015 |
| CVE-2026-74851 | High | 0.5% | Before 3.3.9.1 | 3.3.9.1 |
August 28, 2026 |
| CVE-2024-9883 | Medium | 0.4% | Before 3.2.7.1 | 3.2.7.1 |
November 5, 2024 |
| CVE-2026-54191 | High | 0.2% | 3.3.8 and earlier | 3.3.9 |
June 15, 2026 |
| CVE-2023-23790 | High | 0.3% | 2.9.10.2 and earlier | 2.9.11 |
January 20, 2023 |
| CVE-2026-76573 | Medium | 0.2% | 0 to 3.3.9.1 (inclusive) | 3.3.9.2 |
September 5, 2026 |
| CVE-2024-3956 | Medium | 0.4% | 0 to 3.2.1 (inclusive) | 3.2.1.1 |
May 14, 2024 |
| WF-76d850dd-75f3-4671-9561-0e361d09a121 | Medium | — | 2.7.28 and earlier | 2.7.29 |
August 6, 2021 |
| CVE-2023-6965 | Medium | 0.6% | Before 2.7.31.2 2.8 up to (but not including) 2.8.23.2 2.9 up to (but not including) 2.9.19.2 3.0.0 up to (but not including) 3.0.10.2 |
2.7.31.2 |
April 9, 2024 |