Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enfold MEDIUM 5.4
CVE-2024-13695

The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 via the 'attachment_id' param…

Fix: 7.0.0+
Fix from $1,600 2025-02-25
Enfold MEDIUM 5.3
CVE-2024-13693

The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all version…

Fix: 7.0+
Fix from $1,600 2025-02-25
Enfold MEDIUM 5.4
CVE-2024-5061

The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and 'class' para…

Fix: after 6.0.3
Fix from $1,600 2024-08-30
Enfold MEDIUM 6.1
CVE-2024-37199

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kriesi.At Enfold allows Reflected XSS.Th…

Fix: 5.6.10+
Fix from $1,600 2024-07-22
Enfold MEDIUM 6.1
CVE-2023-38400

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold - Responsive Multi-Purpose Theme …

Fix: after 5.6.4
Fix from $1,600 2023-11-30
Enfold MEDIUM 6.1
CVE-2021-24719

The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold version…

Fix: 4.8.4+
Fix from $1,600 2021-10-11
Enfold HIGH 10.0
CVE-2014-7297

Unspecified vulnerability in the folder framework in the Enfold theme before 3.0.1 for WordPress has unknown impact and attack vectors.

Fix: after 3.0
Fix from $1,950 2014-10-13