| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-5427 | Kubio AI Page Builder <= 2.7.2 - Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes | extendthemes | Kubio AI Page Builder | Medium | 5.3 | 2026-04-17 03:36:45 | Deep Dive |
| CVE-2025-62751 | WordPress Vireo theme <= 1.0.24 - Broken Access Control vulnerability | extendthemes | Vireo | Medium | 4.3 | 2025-12-31 16:02:51 | Deep Dive |
| CVE-2025-11747 | Colibri Page Builder <= 1.0.345 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2025-12-19 08:23:41 | Deep Dive |
| CVE-2025-11376 | Colibri Page Builder <= 1.0.335 - Authenticated (Contributor+) Stored Cross-Site Scripting | extendthemes | Colibri Page Builder | Medium | 6.4 | 2025-12-13 04:31:24 | Deep Dive |
| CVE-2025-9560 | Colibri Page Builder <= 1.0.334 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_newsletter Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2025-10-11 02:24:52 | Deep Dive |
| CVE-2025-8487 | Kubio AI Page Builder <= 2.6.3 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation | extendthemes | Kubio AI Page Builder | Medium | 5.4 | 2025-09-19 03:34:48 | Deep Dive |
| CVE-2025-2294 | Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion | extendthemes | Kubio AI Page Builder | Critical | 9.8 | 2025-03-28 04:22:42 | Deep Dive |
| CVE-2024-13516 | Kubio AI Page Builder <= 2.3.5 - Reflected Cross-Site Scripting | extendthemes | Kubio AI Page Builder | Medium | 6.1 | 2025-01-18 05:33:50 | Deep Dive |
| CVE-2024-37458 | WordPress Highlight theme <= 1.0.29 - Cross Site Request Forgery (CSRF) vulnerability | extendthemes | Highlight | Medium | 4.3 | 2025-01-02 12:00:54 | Deep Dive |
| CVE-2024-37431 | WordPress Mesmerize theme <= 1.6.120 - Cross Site Request Forgery (CSRF) vulnerability | extendthemes | Mesmerize | Medium | 4.3 | 2025-01-02 12:00:50 | Deep Dive |
| CVE-2024-5020 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-12-04 08:22:47 | Deep Dive |
| CVE-2024-39661 | WordPress Kubio AI Page Builder plugin <= 2.2.4 - Authenticated Cross Site Scripting (XSS) vulnerability | ExtendThemes | Kubio AI Page Builder | Medium | 6.5 | 2024-08-01 21:41:30 | Deep Dive |
| CVE-2023-3204 | Materialis <= 1.1.24 - Missing Authorization to Limited Arbitrary Options Update | extendthemes | Materialis | Medium | 6.5 | 2024-06-20 02:08:27 | Deep Dive |
| CVE-2024-4451 | Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-06-07 06:52:22 | Deep Dive |
| CVE-2024-5038 | Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-06-06 11:03:03 | Deep Dive |
| CVE-2024-3340 | Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri-gallery-slideshow' Shortcode | extendthemes | Colibri Page Builder | Medium | 5.4 | 2024-05-02 16:52:52 | Deep Dive |
| CVE-2024-3337 | Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri_breadcrumb_element' Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-05-02 16:52:32 | Deep Dive |
| CVE-2024-3338 | Colibri Page Builder <= 1.0.262 - Authenticated (Author+) Stored Cross-Site Scripting | extendthemes | Colibri Page Builder | Medium | 4.4 | 2024-05-02 16:52:00 | Deep Dive |
| CVE-2024-2839 | Colibri Page Builder <= 1.0.263 - Authenticated (Contributor+) Stored Cross-Site Scripting | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-04-02 06:47:44 | Deep Dive |
| CVE-2024-28004 | WordPress Colibri Page Builder plugin <= 1.0.248 - Broken Access Control vulnerability | ExtendThemes | Colibri Page Builder | Medium | 5.4 | 2024-03-28 05:51:25 | Deep Dive |