Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Athemes Addons For Elementor HIGH 8.8
CVE-2025-32158

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Syed Balkhi aThemes Addons f…

Fix: after 1.0.16
Fix from $1,950 2025-04-10
Athemes Addons For Elementor MEDIUM 5.4
CVE-2025-22646

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aThemes Addons for Elementor atheme…

Fix: 1.0.9+
Fix from $1,600 2025-03-27
Athemes Addons For Elementor MEDIUM 5.4
CVE-2024-13547

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up …

Fix: 1.0.13+
Fix from $1,600 2025-02-01
Athemes Addons For Elementor MEDIUM 5.4
CVE-2024-51675

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aThemes Addons for Elementor atheme…

Fix: 1.0.8+
Fix from $1,600 2024-11-09
Sydney Toolbox MEDIUM 5.4
CVE-2024-4473

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and i…

Fix: 1.32+
Fix from $1,600 2024-05-14
Sydney Toolbox MEDIUM 5.4
CVE-2024-4036

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all versions up to, and including, 1.…

Fix: 1.31+
Fix from $1,600 2024-05-02
Sydney Toolbox MEDIUM 5.4
CVE-2024-3208

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to…

Fix: 1.34+
Fix from $1,600 2024-04-09
Sydney Toolbox MEDIUM 5.4
CVE-2024-2936

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in all versions up to, and incl…

Fix: 1.27+
Fix from $1,600 2024-03-29
Sydney Toolbox MEDIUM 5.4
CVE-2024-1447

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aThemes Slider button element in all versions u…

Fix: 1.26+
Fix from $1,600 2024-02-29