Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical0
High0
Medium5
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2024-10-07

CVE-2024-7132 - Coblocks Plugin

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Coblocks

CVE-2024-7132

MEDIUM CVSS 4.8 2024-08-29
Threat Entry Updated 2025-05-16

CVE-2024-4260 - Coblocks Plugin

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.

PLUGIN Coblocks

CVE-2024-4260

MEDIUM CVSS 6.5 2024-07-23
Threat Entry Updated 2024-11-21

CVE-2024-2933 - Coblocks Plugin

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Social Profiles widget in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Coblocks

CVE-2024-2933

MEDIUM CVSS 6.4 2024-06-01
Threat Entry Updated 2025-05-13

CVE-2024-2369 - Coblocks Plugin

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Coblocks

CVE-2024-2369

MEDIUM CVSS 5.4 2024-04-02
Threat Entry Updated 2025-02-13

CVE-2024-1049 - Coblocks Plugin

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Widget's in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on the link value. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Coblocks

CVE-2024-1049

MEDIUM CVSS 6.4 2024-03-23
Scroll to top