Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2025-4370
The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls funct…
Brizy
2.6.21+
MEDIUM 5.4
CVE-2025-32198
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy brizy.This issue affects Bri…
Brizy
after 2.6.14
HIGH 8.8
CVE-2025-26901
Missing Authorization vulnerability in Brizy Brizy Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bri…
Brizy
after 2.6.1
HIGH 8.8
CVE-2025-26902
Cross-Site Request Forgery (CSRF) vulnerability in Brizy Brizy Pro allows Cross Site Request Forgery.This issue affects Brizy Pro: from n/a through 2…
Brizy
after 2.6.1
MEDIUM 5.4
CVE-2024-10322
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and i…
Brizy
2.6.9+
HIGH 8.8
CVE-2024-10960
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' funct…
Brizy
2.6.5+
MEDIUM 6.1
CVE-2025-22763
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Brizy Pro allows Reflected XSS. This i…
Brizy
after 2.6.1
MEDIUM 6.1
CVE-2024-6254
The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to…
Brizy
2.5.2+
HIGH 8.8
CVE-2024-3242
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageCo…
Brizy
2.4.45+
MEDIUM 6.5
CVE-2024-1937
The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_ite…
Brizy
2.4.45+
MEDIUM 5.4
CVE-2024-1164
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget error message and red…
Brizy
2.4.44+
MEDIUM 5.4
CVE-2024-3667
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of multiple widgets in all version…
Brizy
2.4.44+
MEDIUM 6.1
CVE-2024-2087
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in all versions up to, and includ…
Brizy
2.4.44+
MEDIUM 5.4
CVE-2024-1161
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for blocks in all versi…
Brizy
2.4.44+
MEDIUM 5.4
CVE-2024-1940
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versions up to, and including, 2.4…
Brizy
2.4.42+
MEDIUM 5.4
CVE-2024-34814
Cross-Site Request Forgery (CSRF) vulnerability in Unyson Unyson unyson.This issue affects Unyson: from n/a through <= 2.7.29.
Unyson
2.7.31+
HIGH 8.8
CVE-2024-1311
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function…
Brizy
2.4.41+
MEDIUM 5.4
CVE-2024-1293
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media custom block in all versions up to,…
Brizy
2.4.41+
MEDIUM 5.4
CVE-2024-1296
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload in all versions up to, and i…
Brizy
2.4.41+
MEDIUM 5.4
CVE-2024-1291
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL parameter in all versions up to, and…
Brizy
2.4.41+
MEDIUM 6.5
CVE-2024-1165
The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This ma…
Brizy
2.4.40+
MEDIUM 5.4
CVE-2023-51396
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brizy.Io Brizy – Page Builder allows Stored XSS…
Brizy
after 2.4.29
HIGH 8.1
CVE-2020-36714
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versio…
Brizy
after 1.0.125
MEDIUM 5.3
CVE-2023-2897
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit…
Brizy
after 2.4.18
HIGH 7.2
CVE-2022-2219
The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cros…
Unyson
2.7.27+
MEDIUM 5.4
CVE-2022-2040
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to p…
Brizy
2.4.2+
MEDIUM 5.4
CVE-2022-2041
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor …
Brizy
2.4.2+
HIGH 8.8
CVE-2021-38346
The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the …
Brizy Page Builder
after 2.3.11
MEDIUM 6.5
CVE-2021-38345
The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in…
Brizy Page Builder
1.0.1.126+
MEDIUM 5.4
CVE-2021-38344
The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible t…
Brizy Page Builder
after 2.3.11