Gutenberg [gutenberg] < 21.9.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gutenberg gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through <= 21.8.2.
- Affected:
- up to 21.9.0
- Fixed in:
- 21.9.0
- Disclosed:
- Oct 31, 2025
CVE-2025-64354 on NVD →
Gutenberg <= 21.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 21.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 21.8.2
- Fixed in:
- 21.9.0
- Disclosed:
- Oct 25, 2025
CVE-2025-64354 on NVD →
Gutenberg 21.7 - 21.8 - Contributor+ Stored XSS
medium
- Affected:
- 21.7 – 21.9.0
- Fixed in:
- 21.9.0
- Disclosed:
- Oct 25, 2025
CVE-2025-64354 on NVD →
Gutenberg [gutenberg] < 18.6.1
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gutenberg Team Gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through 18.6.0.
- Affected:
- up to 18.6.1
- Fixed in:
- 18.6.1
- Disclosed:
- Jul 21, 2024
CVE-2024-37492 on NVD →
WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting via the Template Part Block in various versions up to 6.5.5 due to insufficient input sanitization and output escaping on the 'tagName' attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 18.6.0
- Fixed in:
- 18.6.1
- Disclosed:
- Jun 24, 2024
CVE-2024-31111 on NVD →
WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block
medium
- Affected:
- up to 18.6.1
- Fixed in:
- 18.6.1
- Disclosed:
- Jun 24, 2024
CVE-2024-31111 on NVD →
Gutenberg 12.9.0 - 18.0.0 - Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block
medium
The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in versions 12.9.0 to 18.0.0 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrar...
- CVSS:
- 6.4
- Affected:
- 12.9.0 – 18.0.0
- Fixed in:
- 18.01
- Disclosed:
- Apr 9, 2024
Gutenberg 12.9.0 - 18.0.0 - Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block
high
- Affected:
- up to 18.01
- Fixed in:
- 18.01
- Disclosed:
- Apr 9, 2024
Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0
unknown
The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in versions 12.9.0 to 18.0.0 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrar...
- Affected:
- 12.9.0 – 18.0.0
- Fixed in:
- 18.0.0
- Disclosed:
- Apr 9, 2024
Gutenberg < 16.8.1 - Contributor+ Stored XSS
medium
- Affected:
- 16.1 – 16.8.1
- Fixed in:
- 16.8.1
- Disclosed:
- Nov 17, 2023
Gutenberg < 16.8.1 - Contributor+ Stored XSS via Navigation Links Block
medium
- Affected:
- up to 16.8.1
- Fixed in:
- 16.8.1
- Disclosed:
- Oct 13, 2023
CVE-2023-38000 on NVD →
Gutenberg [gutenberg] < 16.8.1
unknown
[en] Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.
- Affected:
- up to 16.8.1
- Fixed in:
- 16.8.1
- Disclosed:
- Oct 13, 2023
CVE-2023-38000 on NVD →
WordPress Core 5.9-6.3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Navigation Attributes
medium
WordPress Core is vulnerable to Stored Cross-Site Scripting via the arrow navigation block attributes in versions between 5.9 and 6.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level privileges and above to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 16.8.0
- Fixed in:
- 16.8.1
- Disclosed:
- Oct 12, 2023
CVE-2023-38000 on NVD →
WordPress Core < 6.0.3 & Gutenberg < 14.3.1 - Authenticated Cross-Site Scripting in Various Blocks
medium
WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to Stored Cross-Site Scripting due to insufficient output escaping on user supplied input. The RSS widget, Search Block, Featured Image Block, RSS Block, and Navigation Block are all affected components...
- CVSS:
- 6.4
- Affected:
- up to 14.3.0
- Fixed in:
- 14.3.1
- Disclosed:
- Oct 18, 2022
CVE-2022-43500 on NVD →
Gutenberg [gutenberg] < 14.3.1
unknown
Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Search, Feature Image, RSS, and Widget blocks were discovered by Alex Concha (WP Security team) and a third-party audit in the WordPress Gutenberg plugin (versions <= 14.3.1).
Update the WordPress Gutenberg plugin to the latest available version (at least 1...
- Affected:
- up to 14.3.1
- Fixed in:
- 14.3.1
- Disclosed:
- Oct 18, 2022
Gutenberg [gutenberg] < 14.3.1
unknown
WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to Stored Cross-Site Scripting due to insufficient output escaping on user supplied input. The RSS widget, Search Block, Featured Image Block, RSS Block, and Navigation Block are all affected components...
- Affected:
- up to 14.3.1
- Fixed in:
- 14.3.1
- Disclosed:
- Oct 18, 2022
Gutenberg < 14.3.1 - Multiple Stored XSS
medium
- Affected:
- up to 14.3.1
- Fixed in:
- 14.3.1
- Disclosed:
- Oct 17, 2022
Gutenberg [gutenberg] <= 17.3.0 (unfixed)
unknown
[en] The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents...
- Affected:
- up to 17.3.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 30, 2022
CVE-2022-33994 on NVD →
WordPress Core < 5.9.2 & Gutenberg < 12.7.2 - Prototype Pollution via Block Editor
medium
WordPress Core in various versions < 5.9.2 and Gutenberg versions less than 12.7.2 are vulnerable to prototype pollution via the block editor which could make injecting malicious web scripts possible in some cases.
- CVSS:
- 5.4
- Affected:
- up to 12.7.2
- Fixed in:
- 12.7.2
- Disclosed:
- Mar 11, 2022
WordPress < 5.9.2 / Gutenberg < 12.7.2 - Prototype Pollution via Gutenberg’s wordpress/url package
unknown
- Affected:
- up to 12.7.2
- Fixed in:
- 12.7.2
- Disclosed:
- Mar 11, 2022
Gutenberg [gutenberg] < 12.7.2
unknown
WordPress Core in various versions < 5.9.2 and Gutenberg versions less than 12.7.2 are vulnerable to prototype pollution via the block editor which could make injecting malicious web scripts possible in some cases.
- Affected:
- up to 12.7.2
- Fixed in:
- 12.7.2
- Disclosed:
- Mar 11, 2022
Gutenberg [gutenberg] < 12.7.2
unknown
Stored Cross-Site Scripting (XSS) vulnerability discovered by Ben Bidner in WordPress Gutenberg plugin (versions <= 12.7.1).
- Affected:
- up to 12.7.2
- Fixed in:
- 12.7.2
- Disclosed:
- Mar 11, 2022
WordPress (5.9-5.9.1) / Gutenberg (9.8.0-12.7.1) - Contributor+ Stored Cross-Site Scripting
medium
- Affected:
- 9.8.0 – 12.7.2
- Fixed in:
- 12.7.2
- Disclosed:
- Mar 11, 2022
Gutenberg [gutenberg] < 14.3.1
unknown
The plugin does not escape data from some blocks before outputting ti back in pages, which could lead to Stored XSS issues.
Affected blocks: Search, Feature Image, RSS and Widget
- Affected:
- up to 14.3.1
- Fixed in:
- 14.3.1
Gutenberg [gutenberg] < 16.8.1
unknown
The plugin does not adequately escape the content of the footnotes within the paragraph block of the block editor, leading to a Contributor+ Cross-Site Scripting vulnerability.
- Affected:
- up to 16.8.1
- Fixed in:
- 16.8.1
Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0
unknown
Update the WordPress Gutenberg plugin to the latest available version (at least 18.1.0).
John Blackbourn discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gutenberg Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML...
- Affected:
- 12.9.0 – 18.0.0
- Fixed in:
- 18.0.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database