CVE-2025-11747
- EPSS 0.04%
- Veröffentlicht 19.12.2025 08:23:41
- Zuletzt bearbeitet 19.12.2025 18:00:18
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied ...
CVE-2025-11376
- EPSS 0.04%
- Veröffentlicht 13.12.2025 04:31:23
- Zuletzt bearbeitet 15.12.2025 18:22:13
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization and output escaping on user supp...
CVE-2025-59593
- EPSS 0.02%
- Veröffentlicht 22.10.2025 14:32:39
- Zuletzt bearbeitet 30.01.2026 16:16:11
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder colibri-page-builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through < 1.0.334.
CVE-2025-9560
- EPSS 0.05%
- Veröffentlicht 11.10.2025 02:24:51
- Zuletzt bearbeitet 14.10.2025 19:36:59
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input sanitization and output escaping on user ...
CVE-2025-32185
- EPSS 0.13%
- Veröffentlicht 04.04.2025 16:15:28
- Zuletzt bearbeitet 07.01.2026 14:12:59
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder allows Stored XSS. This issue affects Colibri Page Builder: from n/a through 1.0.319.
CVE-2024-5020
- EPSS 0.25%
- Veröffentlicht 04.12.2024 09:15:04
- Zuletzt bearbeitet 04.12.2024 09:15:04
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplie...
CVE-2024-4451
- EPSS 0.31%
- Veröffentlicht 07.06.2024 07:15:46
- Zuletzt bearbeitet 21.11.2024 09:42:51
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on use...
CVE-2024-5038
- EPSS 0.23%
- Veröffentlicht 06.06.2024 11:15:48
- Zuletzt bearbeitet 21.11.2024 09:46:49
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attribu...
CVE-2024-3338
- EPSS 0.24%
- Veröffentlicht 02.05.2024 17:15:25
- Zuletzt bearbeitet 28.01.2025 18:09:40
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter in all versions up to, and including, 1.0.262 due to insufficient input sanitization and output escaping. This makes it possible f...
CVE-2024-3340
- EPSS 0.25%
- Veröffentlicht 02.05.2024 17:15:25
- Zuletzt bearbeitet 28.01.2025 18:07:32
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gallery-slideshow' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping...