Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-3075 The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ele… Website Builder 3.29.1+ Fix from $1,6002025-07-29 MEDIUM 5.4 CVE-2025-3076 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text’ parameter in all versions u… Elementor Page Builder 3.29.1+ Fix from $1,6002025-06-10 HIGH 7.2 CVE-2025-1319 The Site Mailer – SMTP Replacement, Email API Deliverability & Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver… Site Mailer 1.2.4+ Fix from $1,9502025-02-28 MEDIUM 5.4 CVE-2024-54444 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor a… Website Builder after 3.25.10 Fix from $1,6002025-02-25 MEDIUM 5.4 CVE-2024-13445 The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margi… Website Builder 3.27.5+ Fix from $1,6002025-02-20 MEDIUM 6.5 CVE-2024-8494 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 … Website Builder 3.25.11+ Fix from $1,6002025-01-30 MEDIUM 5.4 CVE-2024-10453 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typo… Website Builder after 3.25.9 Fix from $1,6002024-12-21 MEDIUM 5.4 CVE-2024-8236 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ paramet… Website Builder after 3.25.7 Fix from $1,6002024-11-26 MEDIUM 5.4 CVE-2024-5416 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter… Website Builder 3.24.0+ Fix from $1,6002024-09-11 MEDIUM 6.1 CVE-2024-35656 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elementor Elementor Pro allows Reflected… Elementor Pro 3.21.3+ Fix from $1,6002024-07-22 MEDIUM 5.4 CVE-2024-37437 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor.T… Website Builder 3.22.2+ Fix from $1,6002024-07-09 MEDIUM 5.4 CVE-2024-4619 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘ho… Website Builder 3.21.5+ Fix from $1,6002024-05-21 HIGH 8.1 CVE-2024-24934 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulati… Website Builder 3.19.1+ Fix from $1,9502024-05-17 MEDIUM 5.4 CVE-2024-4107 The Elementor Website Builder – More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several p… Website Builder 3.21.1+ Fix from $1,6002024-05-14 CRITICAL 9.8 CVE-2023-47504 Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This iss… Website Builder 3.16.5+ Fix from $2,3002024-04-24 MEDIUM 5.4 CVE-2024-2117 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path… Website Builder 3.20.3+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-2781 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_html_tag attribute in all versions … Elementor Pro 3.20.2+ Fix from $1,6002024-03-27 MEDIUM 5.4 CVE-2024-2120 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Navigation widget in all ve… Website Builder 3.20.2+ Fix from $1,6002024-03-27 MEDIUM 5.4 CVE-2024-2121 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Carousel widget in all ver… Elementor Pro 3.20.2+ Fix from $1,6002024-03-27 MEDIUM 5.4 CVE-2024-1364 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget's custom_id in all versions up to, and… Elementor Pro 3.20.2+ Fix from $1,6002024-03-27 MEDIUM 5.4 CVE-2024-1521 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an SVGZ file uploaded via the Form widget in … Elementor Pro 3.20.2+ Fix from $1,6002024-03-27 HIGH 8.8 CVE-2023-48777 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder… Website Builder 3.18.2+ Fix from $1,9502024-03-26 MEDIUM 5.4 CVE-2024-0506 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[… Website Builder 3.19.0+ Fix from $1,6002024-02-29 MEDIUM 5.4 CVE-2023-47505EPSS 25% Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scrip… Website Builder after 3.16.4 Fix from $1,6002023-11-30 MEDIUM 6.1 CVE-2022-4953 The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be us… Website Builder 3.5.5+ Fix from $1,6002023-08-14 HIGH 8.8 CVE-2023-3124EPSS 23% The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option fu… Elementor Pro 3.11.7+ Fix from $1,9502023-06-07 MEDIUM 5.4 CVE-2020-36703 The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and includin… Website Builder after 2.9.7 Fix from $1,6002023-06-07 HIGH 7.2 CVE-2023-0329EPSS 20% The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module befo… Website Builder 3.12.2+ Fix from $1,9502023-05-30 MEDIUM 6.1 CVE-2022-29455EPSS 23% DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions. Website Builder after 3.5.5 Fix from $1,6002022-06-13 HIGH 8.8 CVE-2022-1329EPSS 93% The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check … Website Builder after 3.6.2 Fix from $1,9502022-04-19