Brizy

Brizy

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 05.06.2024 07:15:45
  • Zuletzt bearbeitet 16.01.2025 15:08:00

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget error message and redirect URL in all versions up to, and including, 2.4.43 due to insufficient input sanitization and out...

  • EPSS 0.17%
  • Veröffentlicht 05.06.2024 06:15:11
  • Zuletzt bearbeitet 16.01.2025 15:08:00

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of multiple widgets in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping on user sup...

  • EPSS 1.68%
  • Veröffentlicht 05.06.2024 06:15:10
  • Zuletzt bearbeitet 16.01.2025 15:08:00

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping. This makes it possible for un...

  • EPSS 0.11%
  • Veröffentlicht 05.06.2024 06:15:09
  • Zuletzt bearbeitet 16.01.2025 15:08:00

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versions up to, and including, 2.4.41 due to insufficient input sanitization performed only on the client side and insufficient output ...

  • EPSS 0.15%
  • Veröffentlicht 05.06.2024 06:15:09
  • Zuletzt bearbeitet 16.01.2025 15:08:00

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for blocks in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping. This mak...

  • EPSS 0.27%
  • Veröffentlicht 23.05.2024 06:15:10
  • Zuletzt bearbeitet 16.01.2025 15:27:04

The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capability check on the functions action_request_disable, action_change_template, and action_request_enable in all versions up to, and ...

  • EPSS 9.63%
  • Veröffentlicht 13.03.2024 16:15:19
  • Zuletzt bearbeitet 16.01.2025 15:27:31

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and including, 2.4.40. This makes it possible for authenticated attackers, wi...

  • EPSS 0.19%
  • Veröffentlicht 13.03.2024 16:15:19
  • Zuletzt bearbeitet 16.01.2025 15:27:56

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping on user supplied attribut...

  • EPSS 0.2%
  • Veröffentlicht 13.03.2024 16:15:19
  • Zuletzt bearbeitet 16.01.2025 15:28:17

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media custom block in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping. This makes it poss...

  • EPSS 0.2%
  • Veröffentlicht 13.03.2024 16:15:18
  • Zuletzt bearbeitet 16.01.2025 15:28:37

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL parameter in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping. This makes it possible...