Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Blocksy HIGH 8.8
CVE-2024-37469

Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy allows Cross Site Request Forgery.This issue affects Blocksy: fro…

Fix: 2.0.23+
Fix from $1,950 2025-01-02
Blocksy MEDIUM 5.4
CVE-2024-11420

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Info Block link parameter in all versions up to, and inc…

Fix: 2.0.78+
Fix from $1,600 2024-12-05
Blocksy MEDIUM 5.4
CVE-2024-5439

The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all versions up to, and including, 2.…

Fix: 2.0.51+
Fix from $1,600 2024-06-05
Blocksy MEDIUM 5.4
CVE-2024-4943

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘has_field_link_rel’ parameter in all versions up to, and includ…

Fix: 2.0.47+
Fix from $1,600 2024-05-21
Blocksy Companion MEDIUM 5.4
CVE-2024-4487

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 2.0.45 due …

Fix: 2.0.46+
Fix from $1,600 2024-05-14
Blocksy MEDIUM 5.4
CVE-2024-4158

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 2.0.42 due…

Fix: 2.0.43+
Fix from $1,600 2024-05-14
Blocksy MEDIUM 5.4
CVE-2024-3747

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the className parameter in the About Me block in all versions up to,…

Fix: 2.0.40+
Fix from $1,600 2024-05-02
Blocksy MEDIUM 5.4
CVE-2024-32961

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq Blocksy blocksy.This issue aff…

Fix: 2.0.34+
Fix from $1,600 2024-04-25
Blocksy HIGH 8.8
CVE-2024-31382

Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through <= 2.0.22.

Fix: 2.0.23+
Fix from $1,950 2024-04-15
Blocksy Companion HIGH 8.8
CVE-2024-31932

Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy Companion.This issue affects Blocksy Companion: from n/a through 2.0.28.

Fix: 2.0.29+
Fix from $1,950 2024-04-11
Blocksy Companion MEDIUM 6.4
CVE-2024-2392

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and…

Fix: 2.0.32+
Fix from $1,600 2024-03-22
Blocksy MEDIUM 5.4
CVE-2024-1767

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.0.26 due…

Fix: 2.0.27+
Fix from $1,600 2024-03-09
Blocksy MEDIUM 5.4
CVE-2024-24871

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq Blocksy blocksy.This issue aff…

Fix: after 2.0.19
Fix from $1,600 2024-02-08
Blocksy Companion MEDIUM 5.4
CVE-2023-23898

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions.

Fix: 1.8.68+
Fix from $1,600 2023-04-06