CVE-2025-68900
- EPSS 0.01%
- Veröffentlicht 22.01.2026 16:52:12
- Zuletzt bearbeitet 27.01.2026 21:15:56
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold enfold allows DOM-Based XSS.This issue affects Enfold: from n/a through <= 7.1.3.
CVE-2025-66053
- EPSS 0.05%
- Veröffentlicht 21.11.2025 12:29:53
- Zuletzt bearbeitet 20.01.2026 15:18:59
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold enfold allows Stored XSS.This issue affects Enfold: from n/a through <= 7.1.2.
CVE-2024-13693
- EPSS 0.46%
- Veröffentlicht 25.02.2025 10:15:09
- Zuletzt bearbeitet 28.02.2025 01:30:32
The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avi...
CVE-2024-13695
- EPSS 0.1%
- Veröffentlicht 25.02.2025 10:15:09
- Zuletzt bearbeitet 28.02.2025 01:30:32
The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 via the 'attachment_id' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to ...
CVE-2024-5061
- EPSS 0.31%
- Veröffentlicht 30.08.2024 04:15:07
- Zuletzt bearbeitet 03.09.2024 15:11:56
The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and 'class' parameters in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output ...
CVE-2024-37199
- EPSS 0.17%
- Veröffentlicht 22.07.2024 10:15:05
- Zuletzt bearbeitet 21.11.2024 09:23:23
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kriesi.At Enfold allows Reflected XSS.This issue affects Enfold: from n/a through 5.6.9.
CVE-2023-38400
- EPSS 0.19%
- Veröffentlicht 30.11.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:13:29
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold - Responsive Multi-Purpose Theme allows Reflected XSS.This issue affects Enfold - Responsive Multi-Purpose Theme: from n/a through 5.6...
CVE-2021-24719
- EPSS 0.31%
- Veröffentlicht 11.10.2021 11:15:09
- Zuletzt bearbeitet 21.11.2024 05:53:37
The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.
- EPSS 1.54%
- Veröffentlicht 13.10.2014 10:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in the folder framework in the Enfold theme before 3.0.1 for WordPress has unknown impact and attack vectors.