plugin

Colibri Page Builder Vulnerabilities

38 known security issues reported for the Colibri Page Builder WordPress plugin. Most recent disclosed Dec 19, 2025.

1 high 18 medium

Running Colibri Page Builder on your site? Check whether your installed version is affected.

Scan your site free

Colibri Page Builder [colibri-page-builder] < 1.0.358

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...

Affected:
up to 1.0.358
Fixed in:
1.0.358
Disclosed:
Dec 19, 2025

CVE-2025-11747 on NVD →

Colibri Page Builder <= 1.0.345 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...

CVSS:
6.4
Affected:
up to 1.0.345
Fixed in:
1.0.358
Disclosed:
Dec 18, 2025

CVE-2025-11747 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.342

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...

Affected:
up to 1.0.342
Fixed in:
1.0.342
Disclosed:
Dec 13, 2025

CVE-2025-11376 on NVD →

Colibri Page Builder <= 1.0.335 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...

CVSS:
6.4
Affected:
up to 1.0.335
Fixed in:
1.0.342
Disclosed:
Dec 12, 2025

CVE-2025-11376 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.334

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder colibri-page-builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through < 1.0.334.

Affected:
up to 1.0.334
Fixed in:
1.0.334
Disclosed:
Oct 22, 2025

CVE-2025-59593 on NVD →

Colibri Page Builder <= 1.0.334 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_newsletter Shortcode

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...

CVSS:
6.4
Affected:
up to 1.0.334
Fixed in:
1.0.335
Disclosed:
Oct 10, 2025

CVE-2025-9560 on NVD →

Colibri Page Builder < 1.0.334 - Authenticated (Shop manager+) Stored Cross-Site Scripting

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.0.334 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that wil...

CVSS:
4.4
Affected:
up to 1.0.334
Fixed in:
1.0.334
Disclosed:
Sep 22, 2025

CVE-2025-59593 on NVD →

Colibri Page Builder <= 1.0.319 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.319 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...

CVSS:
6.4
Affected:
up to 1.0.319
Fixed in:
1.0.332
Disclosed:
Apr 4, 2025

CVE-2025-32185 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.332

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder allows Stored XSS. This issue affects Colibri Page Builder: from n/a through 1.0.319.

Affected:
up to 1.0.332
Fixed in:
1.0.332
Disclosed:
Apr 4, 2025

CVE-2025-32185 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.288

unknown

[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

Affected:
up to 1.0.288
Fixed in:
1.0.288
Disclosed:
Dec 4, 2024

CVE-2024-5020 on NVD →

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 1.0.286
Fixed in:
1.0.288
Disclosed:
Dec 3, 2024

CVE-2024-5020 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.277

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...

Affected:
up to 1.0.277
Fixed in:
1.0.277
Disclosed:
Jun 7, 2024

CVE-2024-4451 on NVD →

Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player Shortcode

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 1.0.276
Fixed in:
1.0.277
Disclosed:
Jun 6, 2024

CVE-2024-4451 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.277

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...

Affected:
up to 1.0.277
Fixed in:
1.0.277
Disclosed:
Jun 6, 2024

CVE-2024-5038 on NVD →

Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...

CVSS:
6.4
Affected:
up to 1.0.276
Fixed in:
1.0.277
Disclosed:
Jun 5, 2024

CVE-2024-5038 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.264

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter in all versions up to, and including, 1.0.262 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, t...

Affected:
up to 1.0.264
Fixed in:
1.0.264
Disclosed:
May 2, 2024

CVE-2024-3338 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.274

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_breadcrumb_element' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...

Affected:
up to 1.0.274
Fixed in:
1.0.274
Disclosed:
May 2, 2024

CVE-2024-3337 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.274

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gallery-slideshow' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...

Affected:
up to 1.0.274
Fixed in:
1.0.274
Disclosed:
May 2, 2024

CVE-2024-3340 on NVD →

Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri_breadcrumb_element' Shortcode

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_breadcrumb_element' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...

CVSS:
6.4
Affected:
up to 1.0.272
Fixed in:
1.0.274
Disclosed:
Apr 22, 2024

CVE-2024-3337 on NVD →

Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri-gallery-slideshow' Shortcode

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gallery-slideshow' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

CVSS:
5.4
Affected:
up to 1.0.272
Fixed in:
1.0.274
Disclosed:
Apr 22, 2024

CVE-2024-3340 on NVD →

Colibri Page Builder <= 1.0.262 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter in all versions up to, and including, 1.0.262 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inj...

CVSS:
4.4
Affected:
up to 1.0.262
Fixed in:
1.0.264
Disclosed:
Apr 22, 2024

CVE-2024-3338 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.270

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_post_title' shortcode in all versions up to, and including, 1.0.263 due to insufficient input sanitization and output escaping on user supplied attributes such as 'heading_type'. This makes it possi...

Affected:
up to 1.0.270
Fixed in:
1.0.270
Disclosed:
Apr 2, 2024

CVE-2024-2839 on NVD →

Colibri Page Builder <= 1.0.263 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_post_title' shortcode in all versions up to, and including, 1.0.263 due to insufficient input sanitization and output escaping on user supplied attributes such as 'heading_type'. This makes it possible f...

CVSS:
6.4
Affected:
up to 1.0.263
Fixed in:
1.0.270
Disclosed:
Apr 1, 2024

CVE-2024-2839 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.249

unknown

[en] Missing Authorization vulnerability in ExtendThemes Colibri Page Builder.This issue affects Colibri Page Builder: from n/a through 1.0.248.

Affected:
up to 1.0.249
Fixed in:
1.0.249
Disclosed:
Mar 28, 2024

CVE-2024-28004 on NVD →

Colibri Page Builder <= 1.0.248 - Missing Authorization

medium

The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_colibri_page_builder_wpmu_setting AJAX action in all versions up to, and including, 1.0.248. This makes it possible for authenticated attackers, with subscriber-level access...

CVSS:
4.3
Affected:
up to 1.0.248
Fixed in:
1.0.249
Disclosed:
Mar 26, 2024

CVE-2024-28004 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.263

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated attackers, with subscriber access or higher, to upda...

Affected:
up to 1.0.263
Fixed in:
1.0.263
Disclosed:
Mar 9, 2024

CVE-2024-1870 on NVD →

Colibri Page Builder <= 1.0.260 - Missing Authorization

medium

The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated attackers, with subscriber access or higher, to update th...

CVSS:
4.3
Affected:
up to 1.0.260
Fixed in:
1.0.263
Disclosed:
Mar 8, 2024

CVE-2024-1870 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.260

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the apiCall() function. This makes it possible for unauthenticated attackers to call a limited set of functions that can b...

Affected:
up to 1.0.260
Fixed in:
1.0.260
Disclosed:
Feb 23, 2024

CVE-2024-1361 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.260

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the cp_shortcode_refresh() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes...

Affected:
up to 1.0.260
Fixed in:
1.0.260
Disclosed:
Feb 23, 2024

CVE-2024-1362 on NVD →

Colibri Page Builder <= 1.0.253 - Cross-Site Request Fogery via cp_shortcode_refresh

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the cp_shortcode_refresh() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes via a...

CVSS:
4.3
Affected:
up to 1.0.253
Fixed in:
1.0.260
Disclosed:
Feb 22, 2024

CVE-2024-1362 on NVD →

Colibri Page Builder <= 1.0.253 - Cross-Site Request Fogery via extend_builder

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the apiCall() function. This makes it possible for unauthenticated attackers to call a limited set of functions that can be use...

CVSS:
4.3
Affected:
up to 1.0.253
Fixed in:
1.0.260
Disclosed:
Feb 22, 2024

CVE-2024-1361 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.240

unknown

[en] The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_builder_render_js shortcode in all versions up to, and including, 1.0.239 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat...

Affected:
up to 1.0.240
Fixed in:
1.0.240
Disclosed:
Jan 11, 2024

CVE-2023-6988 on NVD →

Colibri Page Builder <= 1.0.239 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_builder_render_js shortcode in all versions up to, and including, 1.0.239 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at...

CVSS:
6.4
Affected:
up to 1.0.239
Fixed in:
1.0.240
Disclosed:
Dec 23, 2023

CVE-2023-6988 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.241

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExtendThemes Colibri Page Builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through 1.0.239.

Affected:
up to 1.0.241
Fixed in:
1.0.241
Disclosed:
Dec 21, 2023

CVE-2023-50833 on NVD →

Colibri Page Builder <= 1.0.240 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0.240 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 1.0.240
Fixed in:
1.0.241
Disclosed:
Dec 19, 2023

CVE-2023-50833 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.229

unknown

[en] The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.0.227 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers w...

Affected:
up to 1.0.229
Fixed in:
1.0.229
Disclosed:
Aug 31, 2023

CVE-2023-2188 on NVD →

Colibri Page Builder <= 1.0.227 - Authenticated (Administrator+) SQL Injection via post_id

high

The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.0.227 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with a...

CVSS:
7.2
Affected:
up to 1.0.227
Fixed in:
1.0.229
Disclosed:
Jun 22, 2023

CVE-2023-2188 on NVD →

Colibri Page Builder [colibri-page-builder] < 1.0.335

unknown
Affected:
up to 1.0.335
Fixed in:
1.0.335

CVE-2025-9560 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database