Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High1
Medium3
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2026-07-16

CVE-2026-12978 - Funnelkit Plugin

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered when the Divi /builder is active.

PLUGIN Funnelkit

CVE-2026-12978

HIGH CVSS 7.1 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12979 - Funnelkit Plugin

The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal, which can disable other FunnelKit WordPress plugin before 3.15.0.6 or (denial of service).

PLUGIN Funnelkit

CVE-2026-12979

MEDIUM CVSS 5.5 2026-07-16
Threat Entry Updated 2025-11-06

CVE-2025-10567 - Funnelkit Plugin

The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.

PLUGIN Funnelkit

CVE-2025-10567

MEDIUM CVSS 6.3 2025-11-05
Threat Entry Updated 2025-06-12

CVE-2025-2203 - Funnelkit Plugin

The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

PLUGIN Funnelkit

CVE-2025-2203

MEDIUM CVSS 6.1 2025-05-15
Scroll to top