Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Brizy MEDIUM 5.3
CVE-2025-4370

The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls funct…

Fix: 2.6.21+
Fix from $1,600 2025-07-29
Brizy MEDIUM 5.4
CVE-2025-32198

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy brizy.This issue affects Bri…

Fix: after 2.6.14
Fix from $1,600 2025-04-10
Brizy HIGH 8.8
CVE-2025-26901

Missing Authorization vulnerability in Brizy Brizy Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bri…

Fix: after 2.6.1
Fix from $1,950 2025-04-09
Brizy HIGH 8.8
CVE-2025-26902

Cross-Site Request Forgery (CSRF) vulnerability in Brizy Brizy Pro allows Cross Site Request Forgery.This issue affects Brizy Pro: from n/a through 2…

Fix: after 2.6.1
Fix from $1,950 2025-04-09
Brizy MEDIUM 5.4
CVE-2024-10322

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and i…

Fix: 2.6.9+
Fix from $1,600 2025-02-12
Brizy HIGH 8.8
CVE-2024-10960

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' funct…

Fix: 2.6.5+
Fix from $1,950 2025-02-12
Brizy MEDIUM 6.1
CVE-2025-22763

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Brizy Pro allows Reflected XSS. This i…

Fix: after 2.6.1
Fix from $1,600 2025-01-21
Brizy MEDIUM 6.1
CVE-2024-6254

The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to…

Fix: 2.5.2+
Fix from $1,600 2024-08-08
Brizy HIGH 8.8
CVE-2024-3242

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageCo…

Fix: 2.4.45+
Fix from $1,950 2024-07-18
Brizy MEDIUM 6.5
CVE-2024-1937

The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_ite…

Fix: 2.4.45+
Fix from $1,600 2024-07-16
Brizy MEDIUM 5.4
CVE-2024-1164

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget error message and red…

Fix: 2.4.44+
Fix from $1,600 2024-06-05
Brizy MEDIUM 5.4
CVE-2024-3667

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of multiple widgets in all version…

Fix: 2.4.44+
Fix from $1,600 2024-06-05
Brizy MEDIUM 6.1
CVE-2024-2087

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in all versions up to, and includ…

Fix: 2.4.44+
Fix from $1,600 2024-06-05
Brizy MEDIUM 5.4
CVE-2024-1161

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for blocks in all versi…

Fix: 2.4.44+
Fix from $1,600 2024-06-05
Brizy MEDIUM 5.4
CVE-2024-1940

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versions up to, and including, 2.4…

Fix: 2.4.42+
Fix from $1,600 2024-06-05
Unyson MEDIUM 5.4
CVE-2024-34814

Cross-Site Request Forgery (CSRF) vulnerability in Unyson Unyson unyson.This issue affects Unyson: from n/a through <= 2.7.29.

Fix: 2.7.31+
Fix from $1,600 2024-05-14
Brizy HIGH 8.8
CVE-2024-1311

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function…

Fix: 2.4.41+
Fix from $1,950 2024-03-13
Brizy MEDIUM 5.4
CVE-2024-1293

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media custom block in all versions up to,…

Fix: 2.4.41+
Fix from $1,600 2024-03-13
Brizy MEDIUM 5.4
CVE-2024-1296

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload in all versions up to, and i…

Fix: 2.4.41+
Fix from $1,600 2024-03-13
Brizy MEDIUM 5.4
CVE-2024-1291

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL parameter in all versions up to, and…

Fix: 2.4.41+
Fix from $1,600 2024-03-13
Brizy MEDIUM 6.5
CVE-2024-1165

The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This ma…

Fix: 2.4.40+
Fix from $1,600 2024-02-26
Brizy MEDIUM 5.4
CVE-2023-51396

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brizy.Io Brizy – Page Builder allows Stored XSS…

Fix: after 2.4.29
Fix from $1,600 2023-12-29
Brizy HIGH 8.1
CVE-2020-36714

The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versio…

Fix: after 1.0.125
Fix from $1,950 2023-10-20
Brizy MEDIUM 5.3
CVE-2023-2897

The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit…

Fix: after 2.4.18
Fix from $1,600 2023-06-09
Unyson HIGH 7.2
CVE-2022-2219

The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cros…

Fix: 2.7.27+
Fix from $1,950 2022-07-25
Brizy MEDIUM 5.4
CVE-2022-2040

The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to p…

Fix: 2.4.2+
Fix from $1,600 2022-06-27
Brizy MEDIUM 5.4
CVE-2022-2041

The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor …

Fix: 2.4.2+
Fix from $1,600 2022-06-27
Brizy Page Builder HIGH 8.8
CVE-2021-38346

The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the …

Fix: after 2.3.11
Fix from $1,950 2021-10-14
Brizy Page Builder MEDIUM 6.5
CVE-2021-38345

The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in…

Fix: 1.0.1.126+
Fix from $1,600 2021-10-14
Brizy Page Builder MEDIUM 5.4
CVE-2021-38344

The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible t…

Fix: after 2.3.11
Fix from $1,600 2021-10-14