Vulnerabilidades em ExtendThemes

28 resultados
CVE-2025-2294CRITICALKubio AI Page Builder <= 2.5.1 - Unauthenticated Local File InclusionEPSS 77.3%CVE-2019-25142HIGHMesmerize <= 1.6.89 & Materialis <= 1.0.172 - Authenticated Arbitrary Options UpdateEPSS 1.3%CVE-2023-2188HIGHColibri Page Builder <= 1.0.227 - Authenticated (Administrator+) SQL Injection via post_idEPSS 0.8%CVE-2026-5427MEDIUMKubio AI Page Builder <= 2.7.2 - Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block AttributesEPSS 0.5%CVE-2024-3340MEDIUMColibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri-gallery-slideshow' ShortcodeEPSS 0.4%CVE-2024-3338MEDIUMColibri Page Builder <= 1.0.262 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2024-3337MEDIUMColibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri_breadcrumb_element' ShortcodeEPSS 0.4%CVE-2024-5020MEDIUMMultiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript LibraryEPSS 0.4%CVE-2024-1870MEDIUMColibri Page Builder <= 1.0.260 - Missing AuthorizationEPSS 0.4%CVE-2023-6988MEDIUMColibri Page Builder <= 1.0.239 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.4%CVE-2023-50833MEDIUMWordPress Colibri Page Builder Plugin <= 1.0.239 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2023-3204MEDIUMMaterialis <= 1.1.24 - Missing Authorization to Limited Arbitrary Options UpdateEPSS 0.4%CVE-2024-28004MEDIUMWordPress Colibri Page Builder plugin <= 1.0.248 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-2839MEDIUMColibri Page Builder <= 1.0.263 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-5038MEDIUMColibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.3%CVE-2024-13516MEDIUMKubio AI Page Builder <= 2.3.5 - Reflected Cross-Site ScriptingEPSS 0.3%CVE-2025-11747MEDIUMColibri Page Builder <= 1.0.345 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.3%CVE-2024-4451MEDIUMColibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player ShortcodeEPSS 0.3%CVE-2024-39661MEDIUMWordPress Kubio AI Page Builder plugin <= 2.2.4 - Authenticated Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-8487MEDIUMKubio AI Page Builder <= 2.6.3 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin InstallationEPSS 0.2%