Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2025-3075
The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ele…
Website Builder
3.29.1+
MEDIUM 5.4
CVE-2025-3076
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text’ parameter in all versions u…
Elementor Page Builder
3.29.1+
HIGH 7.2
CVE-2025-1319
The Site Mailer – SMTP Replacement, Email API Deliverability & Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver…
Site Mailer
1.2.4+
MEDIUM 5.4
CVE-2024-54444
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor a…
Website Builder
after 3.25.10
MEDIUM 5.4
CVE-2024-13445
The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margi…
Website Builder
3.27.5+
MEDIUM 6.5
CVE-2024-8494
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 …
Website Builder
3.25.11+
MEDIUM 5.4
CVE-2024-10453
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typo…
Website Builder
after 3.25.9
MEDIUM 5.4
CVE-2024-8236
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ paramet…
Website Builder
after 3.25.7
MEDIUM 5.4
CVE-2024-5416
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter…
Website Builder
3.24.0+
MEDIUM 6.1
CVE-2024-35656
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elementor Elementor Pro allows Reflected…
Elementor Pro
3.21.3+
MEDIUM 5.4
CVE-2024-37437
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor.T…
Website Builder
3.22.2+
MEDIUM 5.4
CVE-2024-4619
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘ho…
Website Builder
3.21.5+
HIGH 8.1
CVE-2024-24934
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulati…
Website Builder
3.19.1+
MEDIUM 5.4
CVE-2024-4107
The Elementor Website Builder – More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several p…
Website Builder
3.21.1+
CRITICAL 9.8
CVE-2023-47504
Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This iss…
Website Builder
3.16.5+
MEDIUM 5.4
CVE-2024-2117
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path…
Website Builder
3.20.3+
MEDIUM 5.4
CVE-2024-2781
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_html_tag attribute in all versions …
Elementor Pro
3.20.2+
MEDIUM 5.4
CVE-2024-2120
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Navigation widget in all ve…
Website Builder
3.20.2+
MEDIUM 5.4
CVE-2024-2121
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Carousel widget in all ver…
Elementor Pro
3.20.2+
MEDIUM 5.4
CVE-2024-1364
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget's custom_id in all versions up to, and…
Elementor Pro
3.20.2+
MEDIUM 5.4
CVE-2024-1521
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an SVGZ file uploaded via the Form widget in …
Elementor Pro
3.20.2+
HIGH 8.8
CVE-2023-48777
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder…
Website Builder
3.18.2+
MEDIUM 5.4
CVE-2024-0506
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[…
Website Builder
3.19.0+
MEDIUM 5.4
CVE-2023-47505EPSS 25%
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scrip…
Website Builder
after 3.16.4
MEDIUM 6.1
CVE-2022-4953
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be us…
Website Builder
3.5.5+
HIGH 8.8
CVE-2023-3124EPSS 23%
The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option fu…
Elementor Pro
3.11.7+
MEDIUM 5.4
CVE-2020-36703
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and includin…
Website Builder
after 2.9.7
HIGH 7.2
CVE-2023-0329EPSS 20%
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module befo…
Website Builder
3.12.2+
MEDIUM 6.1
CVE-2022-29455EPSS 23%
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
Website Builder
after 3.5.5
HIGH 8.8
CVE-2022-1329EPSS 93%
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check …
Website Builder
after 3.6.2