Extendthemes

Colibri Page Builder

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 19.12.2025 08:23:41
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied ...

  • EPSS 0.2%
  • Veröffentlicht 13.12.2025 04:31:23
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization and output escaping on user supp...

  • EPSS 0.21%
  • Veröffentlicht 22.10.2025 14:32:39
  • Zuletzt bearbeitet 27.04.2026 20:16:24

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder colibri-page-builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through < 1.0.334.

  • EPSS 0.21%
  • Veröffentlicht 11.10.2025 02:24:51
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input sanitization and output escaping on user ...

  • EPSS 0.35%
  • Veröffentlicht 04.04.2025 16:15:28
  • Zuletzt bearbeitet 23.04.2026 15:28:43

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder colibri-page-builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through <= 1.0.329.

  • EPSS 0.41%
  • Veröffentlicht 04.12.2024 09:15:04
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplie...

  • EPSS 0.26%
  • Veröffentlicht 07.06.2024 07:15:46
  • Zuletzt bearbeitet 08.04.2026 17:18:54

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on use...

  • EPSS 0.32%
  • Veröffentlicht 06.06.2024 11:15:48
  • Zuletzt bearbeitet 08.04.2026 17:18:59

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attribu...

  • EPSS 0.42%
  • Veröffentlicht 02.05.2024 17:15:25
  • Zuletzt bearbeitet 08.04.2026 18:21:23

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter in all versions up to, and including, 1.0.262 due to insufficient input sanitization and output escaping. This makes it possible f...

  • EPSS 0.45%
  • Veröffentlicht 02.05.2024 17:15:25
  • Zuletzt bearbeitet 08.04.2026 19:21:20

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gallery-slideshow' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping...