Browse 47+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-6127 | Elementor Website Builder <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API | elemntor | Elementor Website Builder – more than just a page builder | Medium | 6.4 | 2026-05-01 05:29:53 | Deep Dive |
| CVE-2025-14732 | Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API | elemntor | Elementor Website Builder – more than just a page builder | Medium | 6.4 | 2026-04-08 01:24:43 | Deep Dive |
| CVE-2026-1206 | Elementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template | elemntor | Elementor Website Builder – more than just a page builder | Medium | 4.3 | 2026-03-26 05:29:33 | Deep Dive |
| CVE-2026-32445 | WordPress Elementor Website Builder plugin <= 3.35.5 - Broken Access Control vulnerability | Elementor | Elementor Website Builder | Low | 2.7 | 2026-03-13 11:42:20 | Deep Dive |
| CVE-2026-32352 | WordPress Elementor Website Builder plugin <= 3.35.5 - Cross Site Scripting (XSS) vulnerability | Elementor | Elementor Website Builder | Medium | 6.5 | 2026-03-13 11:41:59 | Deep Dive |
| CVE-2024-50555 | WordPress Elementor Website Builder plugin <= 3.29.0 - Cross Site Scripting (XSS) vulnerability | Elementor | Elementor Website Builder | Medium | 6.5 | 2026-02-20 15:46:25 | Deep Dive |
| CVE-2025-11220 | Elementor <= 3.33.3 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path | elemntor | Elementor Website Builder – more than just a page builder | Medium | 6.4 | 2025-12-16 11:15:44 | Deep Dive |
| CVE-2025-67588 | WordPress Elementor Website Builder plugin <= 3.33.0 - Broken Access Control vulnerability | Elementor | Elementor Website Builder | Medium | 4.3 | 2025-12-09 14:14:17 | Deep Dive |
| CVE-2025-8081📌 | Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import | elemntor | Elementor Website Builder – more than just a page builder | Medium | 4.9 | 2025-08-12 05:27:09 | Deep Dive |
| CVE-2025-4566 | Elementor <= 3.30.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Path Widget | elemntor | Elementor Website Builder – more than just a page builder | Medium | 6.4 | 2025-07-29 04:23:46 | Deep Dive |
| CVE-2025-3075 | Elementor <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | elemntor | Elementor Website Builder – more than just a page builder | Medium | 6.4 | 2025-07-29 04:23:45 | Deep Dive |
| CVE-2025-3076 | Elementor Pro <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | https://elementor.com/ | Elementor Website Builder Pro | Medium | 6.4 | 2025-06-10 04:23:10 | Deep Dive |
| CVE-2024-54444 | WordPress Elementor plugin <= 3.25.10 - Cross Site Scripting (XSS) vulnerability | Elementor | Elementor Website Builder | Medium | 6.5 | 2025-02-25 14:17:50 | Deep Dive |
| CVE-2024-13445 | Elementor Website Builder – More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | elemntor | Elementor Website Builder – more than just a page builder | Medium | 6.4 | 2025-02-20 04:22:25 | Deep Dive |
| CVE-2024-8494 | Elementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode | https://elementor.com/ | Elementor Website Builder Pro | Medium | 4.3 | 2025-01-30 13:42:05 | Deep Dive |
| CVE-2024-10453 | Elementor Website Builder – More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings | elemntor | Elementor Website Builder – more than just a page builder | Medium | 6.4 | 2024-12-21 09:23:56 | Deep Dive |
| CVE-2024-8236 | Elementor Website Builder – More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | elemntor | Elementor Website Builder – more than just a page builder | Medium | 6.4 | 2024-11-26 13:56:55 | Deep Dive |
| CVE-2024-6757 | Elementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function | elemntor | Elementor Website Builder – more than just a page builder | Medium | 4.3 | 2024-10-15 02:03:52 | Deep Dive |
| CVE-2024-9069 | Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | besnikac | Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) | Medium | 6.4 | 2024-09-25 02:05:07 | Deep Dive |
| CVE-2024-5416 | Elementor Website Builder – More than Just a Page Builder <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets | elemntor | Elementor Website Builder – more than just a page builder | Medium | 5.4 | 2024-09-11 11:32:03 | Deep Dive |