| CVE-2024-0896 | Beaver Builder – WordPress Page Builder <= 2.7.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | Medium | 6.4 | 2024-03-13 15:27:06 | Deep Dive |
| CVE-2024-1684 | Otter Blocks PRO <= 2.6.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via File Field CSS | Themisle | Otter Blocks PRO – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Medium | 6.4 | 2024-03-13 15:27:05 | Deep Dive |
| CVE-2024-1854 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Medium | 6.4 | 2024-03-13 15:27:03 | Deep Dive |
| CVE-2024-1691 | Otter Blocks PRO <= 2.6.3 - Unauthenticated Stored Cross-Site Scripting via SVG Upload | Themisle | Otter Blocks PRO – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Medium | 6.1 | 2024-03-13 15:26:58 | Deep Dive |
| CVE-2024-1462 | Maintenance Page <= 1.0.8 - Security Mechanism Bypass via REST API | themegrill | Maintenance Page | Medium | 5.3 | 2024-03-13 15:26:54 | Deep Dive |
| CVE-2023-6880 | Visual Composer Premium <= 45.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | visualcomposer | Visual Composer Website Builder | Medium | 6.4 | 2024-03-13 15:26:52 | Deep Dive |
| CVE-2024-1293 | Brizy – Page Builder <= 2.4.40 - Authenticated (Contributor+) Stored Cross-Site Scripting | themefusecom | Brizy – Page Builder | Medium | 6.4 | 2024-03-13 15:26:50 | Deep Dive |
| CVE-2024-1296 | Brizy – Page Builder <= 2.4.40 - Authenticated (Contributor+) Stored Cross-Site Scripting | themefusecom | Brizy – Page Builder | Medium | 6.4 | 2024-03-13 15:26:45 | Deep Dive |
| CVE-2024-0871 | Beaver Builder <= 2.7.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | Medium | 5.4 | 2024-03-13 15:26:39 | Deep Dive |
| CVE-2024-0897 | Beaver Builder – WordPress Page Builder <= 2.7.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | Medium | 6.4 | 2024-03-13 15:26:38 | Deep Dive |
| CVE-2024-1370 | Maintenance Page <= 1.0.8 - Missing Authorization to Sensitive Information Exposure | themegrill | Maintenance Page | Medium | 5.3 | 2024-03-13 15:26:37 | Deep Dive |
| CVE-2024-2393 | SourceCodester CRUD without Page Reload add_user.php sql injection | SourceCodester | CRUD without Page Reload | Medium | 6.3 | 2024-03-12 13:00:08 | Deep Dive |
| CVE-2023-4629 | LadiApp <= 4.4 - Cross-Site Request Forgery via save_config() | binhnguyenplus | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Medium | 4.3 | 2024-03-12 09:33:57 | Deep Dive |
| CVE-2023-4729 | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Cross-Site Request Forgery via publish_lp() | binhnguyenplus | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Medium | 4.3 | 2024-03-12 09:33:57 | Deep Dive |
| CVE-2023-4627 | LadiApp <= 4.4 - Missing Authorization via save_config() | binhnguyenplus | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Medium | 4.3 | 2024-03-12 09:33:56 | Deep Dive |
| CVE-2023-4728 | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Missing Authorization on publish_lp() | binhnguyenplus | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Medium | 4.3 | 2024-03-12 09:33:56 | Deep Dive |
| CVE-2023-4626 | WordPress Plugin LadiApp 安全漏洞 | binhnguyenplus | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Medium | 4.3 | 2024-03-12 09:33:55 | Deep Dive |
| CVE-2023-4731 | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Cross-Site Request Forgery via init_endpoint | binhnguyenplus | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Medium | 4.3 | 2024-03-12 09:33:55 | Deep Dive |
| CVE-2023-4628 | LadiApp <= 4.4 - Cross-Site Request Forgery via ladiflow_save_hook() | binhnguyenplus | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Medium | 4.3 | 2024-03-12 09:33:54 | Deep Dive |
| CVE-2024-1870 | Colibri Page Builder <= 1.0.260 - Missing Authorization | extendthemes | Colibri Page Builder | Medium | 4.3 | 2024-03-09 09:37:47 | Deep Dive |