Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bold Page Builder MEDIUM 5.4
CVE-2024-53801

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder …

Fix: 5.2.2+
Fix from $1,600 2024-12-06
Bold Page Builder HIGH 8.8
CVE-2024-50417

Missing Authorization vulnerability in boldthemes Bold Page Builder bold-page-builder allows Exploiting Incorrectly Configured Access Control Securit…

Fix: 5.1.4+
Fix from $1,950 2024-11-19
Bold Page Builder MEDIUM 5.4
CVE-2024-47298

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder …

Fix: 5.1.2+
Fix from $1,600 2024-10-06
Bold Page Builder MEDIUM 5.4
CVE-2024-47391

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder …

Fix: 5.1.1+
Fix from $1,600 2024-10-05
Bold Page Builder MEDIUM 5.4
CVE-2024-7100

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_button shortcode in all versions up to…

Fix: 5.0.3+
Fix from $1,600 2024-07-30
Bold Page Builder MEDIUM 5.4
CVE-2024-2734

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AI features all versions up to, and includin…

Fix: 4.8.9+
Fix from $1,600 2024-04-10
Bold Page Builder MEDIUM 5.4
CVE-2024-2735

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Price List' element in all versions up to, and inclu…

Fix: 4.8.9+
Fix from $1,600 2024-04-10
Bold Page Builder MEDIUM 5.4
CVE-2024-2736

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tags in all versions up to, and including, 4.8.8 due…

Fix: 4.8.9+
Fix from $1,600 2024-04-10
Bold Page Builder MEDIUM 5.4
CVE-2024-2733

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Separator" element in all versions up to, a…

Fix: 4.8.9+
Fix from $1,600 2024-04-10
Bold Page Builder MEDIUM 5.4
CVE-2024-3266

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of widgets in all versions up to, and i…

Fix: 4.8.9+
Fix from $1,600 2024-04-09
Bold Page Builder MEDIUM 5.4
CVE-2024-3267

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_price_list shortcode in all versions u…

Fix: 4.8.9+
Fix from $1,600 2024-04-09
Bold Page Builder MEDIUM 5.4
CVE-2024-30442

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.…

Fix: 4.8.1+
Fix from $1,600 2024-03-29
Bold Page Builder MEDIUM 5.4
CVE-2024-30179

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.…

Fix: 4.7.7+
Fix from $1,600 2024-03-27
Bold Page Builder MEDIUM 5.4
CVE-2024-1157

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in all versions up to, and includ…

Fix: 4.8.1+
Fix from $1,600 2024-02-13
Bold Page Builder MEDIUM 5.4
CVE-2024-1159

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and incl…

Fix: 4.8.1+
Fix from $1,600 2024-02-13
Bold Page Builder MEDIUM 5.4
CVE-2024-1160

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in all versions up to, and includi…

Fix: 4.8.1+
Fix from $1,600 2024-02-13
Bold Page Builder MEDIUM 5.4
CVE-2023-49823

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.…

Fix: after 4.6.1
Fix from $1,600 2023-12-15
Bold Timeline Lite MEDIUM 5.4
CVE-2022-4828

The Bold Timeline Lite WordPress plugin before 1.1.5 does not validate and escape some of its shortcode attributes before outputting them back in the…

Fix: 1.1.5+
Fix from $1,600 2023-01-30
Cost Calculator MEDIUM 6.5
CVE-2021-24820

The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perfor…

Fix: after 1.6
Fix from $1,600 2022-02-28
Bold Page Builder HIGH 8.8
CVE-2021-24579EPSS 8%

The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any v…

Fix: 3.1.6+
Fix from $1,950 2021-08-30
Bello CRITICAL 9.8
CVE-2021-24321EPSS 67%

The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, b…

Fix: 1.6.0+
Fix from $2,300 2021-06-01
Bello MEDIUM 6.1
CVE-2021-24320EPSS 11%

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, …

Fix: 1.6.0+
Fix from $1,600 2021-06-01
Bello MEDIUM 5.4
CVE-2021-24319

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the sh…

Fix: 1.6.0+
Fix from $1,600 2021-06-01
Bold Page Builder HIGH 7.5
CVE-2019-15821EPSS 11%

The bold-page-builder plugin before 2.3.2 for WordPress has no protection against modifying settings and importing data.

Fix: 2.3.2+
Fix from $1,950 2019-08-30