| CVE-2024-10493 | Element Pack Elementor Addons < 5.10.3 - Contributor+ Stored XSS | Unknown | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | - | - | 2024-11-28 06:00:08 | Deep Dive |
| CVE-2024-10868 | Enter Addons – Ultimate Template Builder for Elementor <= 2.1.9 - Authenticated (Contributor+) Post Disclosure | themelooks | Enter Addons – Ultimate Template Builder for Elementor | Medium | 4.3 | 2024-11-23 03:25:53 | Deep Dive |
| CVE-2024-3370 | SQLi in Egebilgi Software's Website Template | Egebilgi Software | Website Template | - | - | 2024-11-18 12:52:44 | Deep Dive |
| CVE-2024-9867 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Map Widget | bdthemes | Element Pack – Widgets, Templates & Addons for Elementor | Medium | 5.4 | 2024-11-05 11:32:22 | Deep Dive |
| CVE-2024-9657 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | bdthemes | Element Pack – Widgets, Templates & Addons for Elementor | Medium | 6.5 | 2024-11-05 11:32:21 | Deep Dive |
| CVE-2024-9868 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate | bdthemes | Element Pack – Widgets, Templates & Addons for Elementor | Medium | 5.4 | 2024-11-02 02:03:09 | Deep Dive |
| CVE-2024-10310 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget | bdthemes | Element Pack – Widgets, Templates & Addons for Elementor | Medium | 6.4 | 2024-11-02 02:03:05 | Deep Dive |
| CVE-2024-49288 | WordPress Email Template Customizer for WooCommerce plugin <= 1.2.9.1 - Cross Site Scripting (XSS) vulnerability | VillaTheme | Email Template Customizer for WooCommerce | Medium | 5.9 | 2024-10-17 19:11:51 | Deep Dive |
| CVE-2024-3373 | SQLi in RSM Design's Website Template | RSM Design | Website Template | - | - | 2024-09-27 14:14:16 | Deep Dive |
| CVE-2024-44062 | WordPress Custom Field Template plugin <= 2.6.5 - Cross Site Scripting (XSS) vulnerability | Hiroaki Miyashita | Custom Field Template | Medium | 6.5 | 2024-09-15 07:58:39 | Deep Dive |
| CVE-2024-7611 | Enter Addons – Ultimate Template Builder for Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Events Card Widget | themelooks | Enter Addons – Ultimate Template Builder for Elementor | Medium | 6.4 | 2024-09-06 13:55:22 | Deep Dive |
| CVE-2024-45390 | @blakeembrey/template vulnerable to code injection when attacker controls template input | blakeembrey | js-template | High | 7.3 | 2024-09-03 19:37:32 | Deep Dive |
| CVE-2024-7247 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets | bdthemes | Element Pack – Widgets, Templates & Addons for Elementor | Medium | 6.4 | 2024-08-13 05:30:55 | Deep Dive |
| CVE-2024-7416 | Reveal Template <= 3.7 - Unauthenticated Full Path Disclosure | coffee2code | Reveal Template | Medium | 5.3 | 2024-08-09 09:30:12 | Deep Dive |
| CVE-2024-4359 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Arbitrary File Read | bdthemes | Element Pack – Widgets, Templates & Addons for Elementor | Medium | 6.5 | 2024-08-09 04:29:50 | Deep Dive |
| CVE-2024-4360 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag | bdthemes | Element Pack – Widgets, Templates & Addons for Elementor | Medium | 6.4 | 2024-08-09 04:29:49 | Deep Dive |
| CVE-2024-4643 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting | bdthemes | Element Pack – Widgets, Templates & Addons for Elementor | Medium | 6.4 | 2024-08-02 09:29:44 | Deep Dive |
| CVE-2024-33933 | WordPress Elementor Header & Footer Builder plugin <= 1.6.35 - Contributor+ DOM-Based Cross Site Scripting (XSS) vulnerability | Brainstorm Force, Nikhil Chavan | Elementor – Header, Footer & Blocks Template | Medium | 6.5 | 2024-07-22 10:04:08 | Deep Dive |
| CVE-2024-37550 | WordPress Template Kit – Export plugin <= 1.0.22 - Cross Site Scripting (XSS) vulnerability | Envato | Template Kit – Export | Medium | 5.9 | 2024-07-21 06:57:25 | Deep Dive |
| CVE-2024-5555 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting | bdthemes | Element Pack – Widgets, Templates & Addons for Elementor | Medium | 6.4 | 2024-07-18 08:33:04 | Deep Dive |