Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Website Builder MEDIUM 5.4
CVE-2025-3075

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ele…

Fix: 3.29.1+
Fix from $1,600 2025-07-29
Elementor Page Builder MEDIUM 5.4
CVE-2025-3076

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text’ parameter in all versions u…

Fix: 3.29.1+
Fix from $1,600 2025-06-10
Site Mailer HIGH 7.2
CVE-2025-1319

The Site Mailer – SMTP Replacement, Email API Deliverability & Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver…

Fix: 1.2.4+
Fix from $1,950 2025-02-28
Website Builder MEDIUM 5.4
CVE-2024-54444

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor a…

Fix: after 3.25.10
Fix from $1,600 2025-02-25
Website Builder MEDIUM 5.4
CVE-2024-13445

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margi…

Fix: 3.27.5+
Fix from $1,600 2025-02-20
Website Builder MEDIUM 6.5
CVE-2024-8494

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 …

Fix: 3.25.11+
Fix from $1,600 2025-01-30
Website Builder MEDIUM 5.4
CVE-2024-10453

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typo…

Fix: after 3.25.9
Fix from $1,600 2024-12-21
Website Builder MEDIUM 5.4
CVE-2024-8236

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ paramet…

Fix: after 3.25.7
Fix from $1,600 2024-11-26
Website Builder MEDIUM 5.4
CVE-2024-5416

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter…

Fix: 3.24.0+
Fix from $1,600 2024-09-11
Elementor Pro MEDIUM 6.1
CVE-2024-35656

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elementor Elementor Pro allows Reflected…

Fix: 3.21.3+
Fix from $1,600 2024-07-22
Website Builder MEDIUM 5.4
CVE-2024-37437

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor.T…

Fix: 3.22.2+
Fix from $1,600 2024-07-09
Website Builder MEDIUM 5.4
CVE-2024-4619

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘ho…

Fix: 3.21.5+
Fix from $1,600 2024-05-21
Website Builder HIGH 8.1
CVE-2024-24934

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulati…

Fix: 3.19.1+
Fix from $1,950 2024-05-17
Website Builder MEDIUM 5.4
CVE-2024-4107

The Elementor Website Builder – More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several p…

Fix: 3.21.1+
Fix from $1,600 2024-05-14
Website Builder CRITICAL 9.8
CVE-2023-47504

Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This iss…

Fix: 3.16.5+
Fix from $2,300 2024-04-24
Website Builder MEDIUM 5.4
CVE-2024-2117

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path…

Fix: 3.20.3+
Fix from $1,600 2024-04-09
Elementor Pro MEDIUM 5.4
CVE-2024-2781

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_html_tag attribute in all versions …

Fix: 3.20.2+
Fix from $1,600 2024-03-27
Website Builder MEDIUM 5.4
CVE-2024-2120

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Navigation widget in all ve…

Fix: 3.20.2+
Fix from $1,600 2024-03-27
Elementor Pro MEDIUM 5.4
CVE-2024-2121

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Carousel widget in all ver…

Fix: 3.20.2+
Fix from $1,600 2024-03-27
Elementor Pro MEDIUM 5.4
CVE-2024-1364

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget's custom_id in all versions up to, and…

Fix: 3.20.2+
Fix from $1,600 2024-03-27
Elementor Pro MEDIUM 5.4
CVE-2024-1521

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an SVGZ file uploaded via the Form widget in …

Fix: 3.20.2+
Fix from $1,600 2024-03-27
Website Builder HIGH 8.8
CVE-2023-48777

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder…

Fix: 3.18.2+
Fix from $1,950 2024-03-26
Website Builder MEDIUM 5.4
CVE-2024-0506

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[…

Fix: 3.19.0+
Fix from $1,600 2024-02-29
Website Builder MEDIUM 5.4
CVE-2023-47505EPSS 25%

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scrip…

Fix: after 3.16.4
Fix from $1,600 2023-11-30
Website Builder MEDIUM 6.1
CVE-2022-4953

The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be us…

Fix: 3.5.5+
Fix from $1,600 2023-08-14
Elementor Pro HIGH 8.8
CVE-2023-3124EPSS 23%

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option fu…

Fix: 3.11.7+
Fix from $1,950 2023-06-07
Website Builder MEDIUM 5.4
CVE-2020-36703

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and includin…

Fix: after 2.9.7
Fix from $1,600 2023-06-07
Website Builder HIGH 7.2
CVE-2023-0329EPSS 20%

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module befo…

Fix: 3.12.2+
Fix from $1,950 2023-05-30
Website Builder MEDIUM 6.1
CVE-2022-29455EPSS 23%

DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.

Fix: after 3.5.5
Fix from $1,600 2022-06-13
Website Builder HIGH 8.8
CVE-2022-1329EPSS 93%

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check …

Fix: after 3.6.2
Fix from $1,950 2022-04-19