| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-11747 | Colibri Page Builder <= 1.0.345 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2025-12-19 08:23:41 | Deep Dive |
| CVE-2025-11376 | Colibri Page Builder <= 1.0.335 - Authenticated (Contributor+) Stored Cross-Site Scripting | extendthemes | Colibri Page Builder | Medium | 6.4 | 2025-12-13 04:31:24 | Deep Dive |
| CVE-2025-59593 | WordPress Colibri Page Builder Plugin < 1.0.334 - Cross Site Scripting (XSS) Vulnerability | Extend Themes | Colibri Page Builder | Medium | 5.9 | 2025-10-22 14:32:40 | Deep Dive |
| CVE-2025-9560 | Colibri Page Builder <= 1.0.334 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_newsletter Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2025-10-11 02:24:52 | Deep Dive |
| CVE-2025-32185 | WordPress Colibri Page Builder plugin <= 1.0.329 - Cross Site Scripting (XSS) vulnerability | Extend Themes | Colibri Page Builder | Medium | 6.5 | 2025-04-04 15:58:59 | Deep Dive |
| CVE-2024-5020 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-12-04 08:22:47 | Deep Dive |
| CVE-2024-4451 | Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-06-07 06:52:22 | Deep Dive |
| CVE-2024-5038 | Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-06-06 11:03:03 | Deep Dive |
| CVE-2024-3340 | Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri-gallery-slideshow' Shortcode | extendthemes | Colibri Page Builder | Medium | 5.4 | 2024-05-02 16:52:52 | Deep Dive |
| CVE-2024-3337 | Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri_breadcrumb_element' Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-05-02 16:52:32 | Deep Dive |
| CVE-2024-3338 | Colibri Page Builder <= 1.0.262 - Authenticated (Author+) Stored Cross-Site Scripting | extendthemes | Colibri Page Builder | Medium | 4.4 | 2024-05-02 16:52:00 | Deep Dive |
| CVE-2024-33686 | Broken Access Control vulnerability affecting multiple WordPress themes by Extend Themes | Extend Themes | Pathway | Medium | 4.3 | 2024-04-29 05:56:42 | Deep Dive |
| CVE-2024-2839 | Colibri Page Builder <= 1.0.263 - Authenticated (Contributor+) Stored Cross-Site Scripting | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-04-02 06:47:44 | Deep Dive |
| CVE-2024-28004 | WordPress Colibri Page Builder plugin <= 1.0.248 - Broken Access Control vulnerability | ExtendThemes | Colibri Page Builder | Medium | 5.4 | 2024-03-28 05:51:25 | Deep Dive |
| CVE-2024-1870 | Colibri Page Builder <= 1.0.260 - Missing Authorization | extendthemes | Colibri Page Builder | Medium | 4.3 | 2024-03-09 09:37:47 | Deep Dive |
| CVE-2024-1360 | Colibri WP <= 1.0.94 - Cross-Site Request Forgery to Limited Plugin Installation | extendthemes | Colibri WP | Medium | 4.3 | 2024-02-23 11:03:47 | Deep Dive |
| CVE-2024-1362 | Colibri Page Builder <= 1.0.253 - Cross-Site Request Fogery via cp_shortcode_refresh | extendthemes | Colibri Page Builder | Medium | 4.3 | 2024-02-23 11:03:46 | Deep Dive |
| CVE-2024-1361 | Colibri Page Builder <= 1.0.253 - Cross-Site Request Fogery via extend_builder | extendthemes | Colibri Page Builder | Medium | 4.3 | 2024-02-23 11:03:46 | Deep Dive |
| CVE-2023-6988 | Colibri Page Builder <= 1.0.239 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-01-11 08:32:31 | Deep Dive |
| CVE-2023-50833 | WordPress Colibri Page Builder Plugin <= 1.0.239 is vulnerable to Cross Site Scripting (XSS) | ExtendThemes | Colibri Page Builder | Medium | 6.5 | 2023-12-21 17:53:56 | Deep Dive |