Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total34
Critical1
High7
Medium26
Reset
Showing 21-34 of 34 records
Threat Entry Updated 2025-01-16

CVE-2024-1940 - Page Builder Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versions up to, and including, 2.4.41 due to insufficient input sanitization performed only on the client side and insufficient output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1940

HIGH CVSS 7.1 2024-06-05
Threat Entry Updated 2025-01-16

CVE-2024-1161 - Page Builder Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for blocks in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1161

MEDIUM CVSS 6.4 2024-06-05
Threat Entry Updated 2025-01-16

CVE-2024-3711 - Page Builder Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capability check on the functions action_request_disable, action_change_template, and action_request_enable in all versions up to, and including, 2.4.43. This makes it possible for authenticated attackers, with contributor access or above, to enable/disable the Brizy editor and modify the template used.

PLUGIN Page Builder

CVE-2024-3711

MEDIUM CVSS 4.3 2024-05-23
Threat Entry Updated 2025-08-12

CVE-2024-4361 - Page Builder Plugin

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 2.29.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-4361

MEDIUM CVSS 6.4 2024-05-21
Threat Entry Updated 2025-05-28

CVE-2024-1842 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1842

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-28

CVE-2024-1841 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1841

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-28

CVE-2024-1840 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1840

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-28

CVE-2024-1805 - Page Builder Plugin

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1805

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-02-13

CVE-2024-2202 - Page Builder Plugin

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and including, 2.29.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-2202

MEDIUM CVSS 6.4 2024-03-23
Threat Entry Updated 2025-01-16

CVE-2024-1311 - Page Builder Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and including, 2.4.40. This makes it possible for authenticated attackers, with contributor access or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Page Builder

CVE-2024-1311

HIGH CVSS 8.8 2024-03-13
Threat Entry Updated 2025-01-16

CVE-2024-1296 - Page Builder Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1296

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-16

CVE-2024-1293 - Page Builder Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media custom block in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1293

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-16

CVE-2024-1291 - Page Builder Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL parameter in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Page Builder

CVE-2024-1291

MEDIUM CVSS 6.4 2024-03-13
Threat Entry Updated 2025-01-16

CVE-2024-1165 - Page Builder Plugin

The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files to arbitrary locations on the server

PLUGIN Page Builder

CVE-2024-1165

MEDIUM CVSS 4.3 2024-02-26
Scroll to top