Community by PeepSo – Download from PeepSo.com

Community by PeepSo – Download from PeepSo.com has 17 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; all 17 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2024 was the busiest year with 8 disclosures.

The most common weakness is Cross-Site Scripting, behind 7 of the records (41%). Other recurring categories include Cross-Site Request Forgery (CSRF), Exposure Of Sensitive Information To An Unauthorized Actor.

Every one of the 17 issues recorded for Community by PeepSo – Download from PeepSo.com has a vendor fix available, so running the current release closes all known holes.

15 independent researchers contributed these findings, most of them (2) reported by Bikram Kharal (themarkib).

01234567891021.06.2016Today21.06.20168.8Community by PeepSo – Social Network, Membership, Registration, User Profiles < 1.6.1 - Privilege Escalation CVSS 8.8 · 21.06.201620.02.20235.4Community by PeepSo <= 6.0.2.0 - Cross Site Request Forgery CVSS 5.4 · 20.02.202322.02.20238.1Community by PeepSo <= 6.0.2.0 - Cross-Site Request Forgery leading to Plugin/Subscription Deletion CVSS 8.1 · 22.02.202305.05.20235.3Community by PeepSo <= 6.0.9.0 - Missing Authorization to Sensitive Information Exposure CVSS 5.3 · 05.05.202312.05.20234.3Community by PeepSo <= 6.0.9.0 - Cross-Site Request Forgery to Field Duplication CVSS 4.3 · 12.05.202316.11.20234.3Community by PeepSo <= 6.1.6.0 - Cross-Site Request Forgery via delete CVSS 4.3 · 16.11.202320.11.20236.4Community by PeepSo <= 6.2.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 20.11.202324.11.20236.1Community by PeepSo <= 6.2.6.0 - Reflected Cross-Site Scripting CVSS 6.1 · 24.11.202309.01.20244.3Community by PeepSo <= 6.3.1.1 - Cross-Site Request Forgery to User Post Creation CVSS 4.3 · 09.01.20246.1Community by PeepSo <= 6.3.1.1 - Reflected Cross-Site Scripting CVSS 6.1 · 09.01.202414.02.20246.5Community by PeepSo <= 6.2.7.0 - Unauthenticated Sensitive Information Disclosure via Log file CVSS 6.5 · 14.02.202409.09.20244.4Community by PeepSo – Social Network, Membership, Registration, User Profiles <= 6.4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 09.09.20244.4Community by PeepSo – Social Network, Membership, Registration, User Profiles <= 6.4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via content Parameter CVSS 4.4 · 09.09.202424.09.20245.3Community by PeepSo – Social Network, Membership, Registration, User Profiles <= 6.4.6.0 - Unauthenticated Full Path Disclosure CVSS 5.3 · 24.09.202415.10.20245.4Community by PeepSo <= 6.4.6.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 5.4 · 15.10.202420.11.20246.1Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App <=7.0.3.0 - Reflected Cross-Site Scripting CVSS 6.1 · 20.11.202419.08.20266.5Community by PeepSo – Download from PeepSo.com <= 9.0.5.2 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 19.08.2026

Strategic Overview

Avg CVSSMedium
5.7/ 10
Patch Coverage100%
Open

0

Fixed

17

Get automatic notifications for all Community by PeepSo – Download from PeepSo.com vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2016-10968

Community by PeepSo – Social Network, Membership, Registration, User Profiles < 1.6.1 - Privilege Escalation

Read the full analysis

Vulnerability Records

17 records
2026-08-19 00:00CVE-2026-66668
6.5
Medium
Ayoub MOUHATTAYes
2024-11-20 13:34CVE-2024-11447
6.1
Medium
rajanhoyrYes
2024-10-15 00:00CVE-2024-9873
5.4
Medium
Bikram Kharal (themarkib)Yes
2024-09-24 12:05CVE-2024-7426
5.3
Medium
stealthcopterYes
2024-09-09 19:11CVE-2024-7618
4.4
Medium
Tieu Pham Trong NhanYes
2024-09-09 19:04CVE-2024-7655
4.4
Medium
Tieu Pham Trong NhanYes
2024-02-14 00:00CVE-2024-25923
6.5
Medium
Joshua ChanYes
2024-01-09 00:00CVE-2023-7125
4.3
Medium
Bikram Kharal (themarkib)Yes
2024-01-09 00:00CVE-2024-0187
6.1
Medium
Erwan LRYes
2023-11-24 00:00CVE-2023-48746
6.1
Medium
PhdYes
Showing 1–10 of 17 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C