Colibri Page Builder [colibri-page-builder] < 1.0.358
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...
- Affected:
- up to 1.0.358
- Fixed in:
- 1.0.358
- Disclosed:
- Dec 19, 2025
CVE-2025-11747 on NVD →
Colibri Page Builder <= 1.0.345 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...
- CVSS:
- 6.4
- Affected:
- up to 1.0.345
- Fixed in:
- 1.0.358
- Disclosed:
- Dec 18, 2025
CVE-2025-11747 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.342
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...
- Affected:
- up to 1.0.342
- Fixed in:
- 1.0.342
- Disclosed:
- Dec 13, 2025
CVE-2025-11376 on NVD →
Colibri Page Builder <= 1.0.335 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...
- CVSS:
- 6.4
- Affected:
- up to 1.0.335
- Fixed in:
- 1.0.342
- Disclosed:
- Dec 12, 2025
CVE-2025-11376 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.334
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder colibri-page-builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through < 1.0.334.
- Affected:
- up to 1.0.334
- Fixed in:
- 1.0.334
- Disclosed:
- Oct 22, 2025
CVE-2025-59593 on NVD →
Colibri Page Builder <= 1.0.334 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_newsletter Shortcode
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...
- CVSS:
- 6.4
- Affected:
- up to 1.0.334
- Fixed in:
- 1.0.335
- Disclosed:
- Oct 10, 2025
CVE-2025-9560 on NVD →
Colibri Page Builder < 1.0.334 - Authenticated (Shop manager+) Stored Cross-Site Scripting
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.0.334 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 4.4
- Affected:
- up to 1.0.334
- Fixed in:
- 1.0.334
- Disclosed:
- Sep 22, 2025
CVE-2025-59593 on NVD →
Colibri Page Builder <= 1.0.319 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.319 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 6.4
- Affected:
- up to 1.0.319
- Fixed in:
- 1.0.332
- Disclosed:
- Apr 4, 2025
CVE-2025-32185 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.332
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder allows Stored XSS. This issue affects Colibri Page Builder: from n/a through 1.0.319.
- Affected:
- up to 1.0.332
- Fixed in:
- 1.0.332
- Disclosed:
- Apr 4, 2025
CVE-2025-32185 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.288
unknown
[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- Affected:
- up to 1.0.288
- Fixed in:
- 1.0.288
- Disclosed:
- Dec 4, 2024
CVE-2024-5020 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 1.0.286
- Fixed in:
- 1.0.288
- Disclosed:
- Dec 3, 2024
CVE-2024-5020 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.277
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...
- Affected:
- up to 1.0.277
- Fixed in:
- 1.0.277
- Disclosed:
- Jun 7, 2024
CVE-2024-4451 on NVD →
Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player Shortcode
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...
- CVSS:
- 6.4
- Affected:
- up to 1.0.276
- Fixed in:
- 1.0.277
- Disclosed:
- Jun 6, 2024
CVE-2024-4451 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.277
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...
- Affected:
- up to 1.0.277
- Fixed in:
- 1.0.277
- Disclosed:
- Jun 6, 2024
CVE-2024-5038 on NVD →
Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...
- CVSS:
- 6.4
- Affected:
- up to 1.0.276
- Fixed in:
- 1.0.277
- Disclosed:
- Jun 5, 2024
CVE-2024-5038 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.264
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter in all versions up to, and including, 1.0.262 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, t...
- Affected:
- up to 1.0.264
- Fixed in:
- 1.0.264
- Disclosed:
- May 2, 2024
CVE-2024-3338 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.274
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_breadcrumb_element' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...
- Affected:
- up to 1.0.274
- Fixed in:
- 1.0.274
- Disclosed:
- May 2, 2024
CVE-2024-3337 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.274
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gallery-slideshow' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...
- Affected:
- up to 1.0.274
- Fixed in:
- 1.0.274
- Disclosed:
- May 2, 2024
CVE-2024-3340 on NVD →
Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri_breadcrumb_element' Shortcode
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_breadcrumb_element' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...
- CVSS:
- 6.4
- Affected:
- up to 1.0.272
- Fixed in:
- 1.0.274
- Disclosed:
- Apr 22, 2024
CVE-2024-3337 on NVD →
Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri-gallery-slideshow' Shortcode
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gallery-slideshow' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 5.4
- Affected:
- up to 1.0.272
- Fixed in:
- 1.0.274
- Disclosed:
- Apr 22, 2024
CVE-2024-3340 on NVD →
Colibri Page Builder <= 1.0.262 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter in all versions up to, and including, 1.0.262 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inj...
- CVSS:
- 4.4
- Affected:
- up to 1.0.262
- Fixed in:
- 1.0.264
- Disclosed:
- Apr 22, 2024
CVE-2024-3338 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.270
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_post_title' shortcode in all versions up to, and including, 1.0.263 due to insufficient input sanitization and output escaping on user supplied attributes such as 'heading_type'. This makes it possi...
- Affected:
- up to 1.0.270
- Fixed in:
- 1.0.270
- Disclosed:
- Apr 2, 2024
CVE-2024-2839 on NVD →
Colibri Page Builder <= 1.0.263 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_post_title' shortcode in all versions up to, and including, 1.0.263 due to insufficient input sanitization and output escaping on user supplied attributes such as 'heading_type'. This makes it possible f...
- CVSS:
- 6.4
- Affected:
- up to 1.0.263
- Fixed in:
- 1.0.270
- Disclosed:
- Apr 1, 2024
CVE-2024-2839 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.249
unknown
[en] Missing Authorization vulnerability in ExtendThemes Colibri Page Builder.This issue affects Colibri Page Builder: from n/a through 1.0.248.
- Affected:
- up to 1.0.249
- Fixed in:
- 1.0.249
- Disclosed:
- Mar 28, 2024
CVE-2024-28004 on NVD →
Colibri Page Builder <= 1.0.248 - Missing Authorization
medium
The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_colibri_page_builder_wpmu_setting AJAX action in all versions up to, and including, 1.0.248. This makes it possible for authenticated attackers, with subscriber-level access...
- CVSS:
- 4.3
- Affected:
- up to 1.0.248
- Fixed in:
- 1.0.249
- Disclosed:
- Mar 26, 2024
CVE-2024-28004 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.263
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated attackers, with subscriber access or higher, to upda...
- Affected:
- up to 1.0.263
- Fixed in:
- 1.0.263
- Disclosed:
- Mar 9, 2024
CVE-2024-1870 on NVD →
Colibri Page Builder <= 1.0.260 - Missing Authorization
medium
The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated attackers, with subscriber access or higher, to update th...
- CVSS:
- 4.3
- Affected:
- up to 1.0.260
- Fixed in:
- 1.0.263
- Disclosed:
- Mar 8, 2024
CVE-2024-1870 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.260
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the apiCall() function. This makes it possible for unauthenticated attackers to call a limited set of functions that can b...
- Affected:
- up to 1.0.260
- Fixed in:
- 1.0.260
- Disclosed:
- Feb 23, 2024
CVE-2024-1361 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.260
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the cp_shortcode_refresh() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes...
- Affected:
- up to 1.0.260
- Fixed in:
- 1.0.260
- Disclosed:
- Feb 23, 2024
CVE-2024-1362 on NVD →
Colibri Page Builder <= 1.0.253 - Cross-Site Request Fogery via cp_shortcode_refresh
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the cp_shortcode_refresh() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes via a...
- CVSS:
- 4.3
- Affected:
- up to 1.0.253
- Fixed in:
- 1.0.260
- Disclosed:
- Feb 22, 2024
CVE-2024-1362 on NVD →
Colibri Page Builder <= 1.0.253 - Cross-Site Request Fogery via extend_builder
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the apiCall() function. This makes it possible for unauthenticated attackers to call a limited set of functions that can be use...
- CVSS:
- 4.3
- Affected:
- up to 1.0.253
- Fixed in:
- 1.0.260
- Disclosed:
- Feb 22, 2024
CVE-2024-1361 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.240
unknown
[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_builder_render_js shortcode in all versions up to, and including, 1.0.239 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat...
- Affected:
- up to 1.0.240
- Fixed in:
- 1.0.240
- Disclosed:
- Jan 11, 2024
CVE-2023-6988 on NVD →
Colibri Page Builder <= 1.0.239 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_builder_render_js shortcode in all versions up to, and including, 1.0.239 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at...
- CVSS:
- 6.4
- Affected:
- up to 1.0.239
- Fixed in:
- 1.0.240
- Disclosed:
- Dec 23, 2023
CVE-2023-6988 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.241
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExtendThemes Colibri Page Builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through 1.0.239.
- Affected:
- up to 1.0.241
- Fixed in:
- 1.0.241
- Disclosed:
- Dec 21, 2023
CVE-2023-50833 on NVD →
Colibri Page Builder <= 1.0.240 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0.240 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 1.0.240
- Fixed in:
- 1.0.241
- Disclosed:
- Dec 19, 2023
CVE-2023-50833 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.229
unknown
[en] The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.0.227 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers w...
- Affected:
- up to 1.0.229
- Fixed in:
- 1.0.229
- Disclosed:
- Aug 31, 2023
CVE-2023-2188 on NVD →
Colibri Page Builder <= 1.0.227 - Authenticated (Administrator+) SQL Injection via post_id
high
The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.0.227 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with a...
- CVSS:
- 7.2
- Affected:
- up to 1.0.227
- Fixed in:
- 1.0.229
- Disclosed:
- Jun 22, 2023
CVE-2023-2188 on NVD →
Colibri Page Builder [colibri-page-builder] < 1.0.335
unknown
- Affected:
- up to 1.0.335
- Fixed in:
- 1.0.335
CVE-2025-9560 on NVD →