Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Page Builder MEDIUM 5.4
CVE-2025-10006

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all version…

Fix: 8.7+
Fix from $1,600 2025-10-18
Page Builder MEDIUM 5.4
CVE-2025-11161

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to…

Fix: 8.7+
Fix from $1,600 2025-10-15
Page Builder MEDIUM 5.4
CVE-2025-11160

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in all versions up to, and inclu…

Fix: 8.7+
Fix from $1,600 2025-10-15
Page Builder MEDIUM 5.4
CVE-2025-7502

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up t…

Fix: 8.6+
Fix from $1,600 2025-08-06
Page Builder MEDIUM 5.4
CVE-2025-4968

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyrig…

Fix: 8.5+
Fix from $1,600 2025-07-24
Page Builder MEDIUM 5.4
CVE-2025-4965

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Builder feature in al…

Fix: 8.5+
Fix from $1,600 2025-06-19
Page Builder MEDIUM 5.4
CVE-2024-43953

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Classic Addons – WPBakery Page B…

Fix: after 3.0
Fix from $1,600 2024-08-29
Page Builder HIGH 8.8
CVE-2024-5709

The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_nam…

Fix: 7.8+
Fix from $1,950 2024-08-06
Wpbakery Page Builder MEDIUM 5.4
CVE-2024-5708

The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and in…

Fix: 7.8+
Fix from $1,600 2024-08-06
Page Builder MEDIUM 5.4
CVE-2024-1842

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and includ…

Fix: 7.6+
Fix from $1,600 2024-05-02
Page Builder MEDIUM 5.4
CVE-2024-1805

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including,…

Fix: 7.6+
Fix from $1,600 2024-05-02
Page Builder MEDIUM 5.4
CVE-2024-1840

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all versions up to, and including…

Fix: 7.6+
Fix from $1,600 2024-05-02
Page Builder MEDIUM 5.4
CVE-2024-1841

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all versions up to, and including,…

Fix: 7.6+
Fix from $1,600 2024-05-02
Page Builder MEDIUM 5.4
CVE-2023-31213

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPBakery Page Builder plugin <= 6.13.0 versions.

Fix: 6.13.0+
Fix from $1,600 2023-06-22
Page Builder MEDIUM 5.4
CVE-2020-28650

The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mecha…

Fix: 6.4.1+
Fix from $1,600 2020-11-16