| CVE-2024-37462 | WordPress Ultimate Bootstrap Elements for Elementor plugin <= 1.4.2 - Local File Inclusion vulnerability | G5Theme | Ultimate Bootstrap Elements for Elementor | High | 8.5 | 2024-07-09 10:50:21 | Deep Dive |
| CVE-2024-6169 | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'username' | unitecms | Unlimited Elements For Elementor | Medium | 6.4 | 2024-07-09 04:32:56 | Deep Dive |
| CVE-2024-6170 | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'email' | unitecms | Unlimited Elements For Elementor | Medium | 6.4 | 2024-07-09 04:32:56 | Deep Dive |
| CVE-2024-6166 | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - Authenticated (Contributor+) Time-Based SQL Injection | unitecms | Unlimited Elements For Elementor | High | 8.8 | 2024-07-09 04:32:54 | Deep Dive |
| CVE-2024-6171 | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - IP Address Spoofing to Antispam Bypass | unitecms | Unlimited Elements For Elementor | Medium | 5.3 | 2024-07-09 04:32:53 | Deep Dive |
| CVE-2024-6071 | PTC Creo Elements/Direct License Server Missing Authorization | PTC | Creo Elements/Direct License | Critical | 10.0 | 2024-06-27 23:05:03 | Deep Dive |
| CVE-2024-4570 | Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting | wpvibes | Addon Elements for Elementor (formerly Elementor Addon Elements) | Medium | 6.4 | 2024-06-27 04:04:33 | Deep Dive |
| CVE-2024-4569 | Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting | wpvibes | Addon Elements for Elementor (formerly Elementor Addon Elements) | Medium | 6.4 | 2024-06-27 04:04:32 | Deep Dive |
| CVE-2023-39993 | WordPress ElementsKit Lite plugin <= 2.9.0 - Broken Access Control vulnerability | Wpmet | Elements kit Elementor addons | Medium | 4.3 | 2024-06-19 12:07:08 | Deep Dive |
| CVE-2024-4615 | Elespare – Blog, Magazine and Newspaper Addons for Elementor with Templates, Widgets, Kits, and Header/Footer Builder. One Click Import: No Coding Required! <= 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Horizontal Nav Menu Widget | elespare | EleSpare – News, Magazine and Blog Addons for Elementor | Medium | 6.4 | 2024-06-13 07:31:53 | Deep Dive |
| CVE-2024-2092 | Elementor Addon Elements <= 1.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Widget | wpvibes | Addon Elements for Elementor (formerly Elementor Addon Elements) | Medium | 5.4 | 2024-06-12 09:33:13 | Deep Dive |
| CVE-2023-31080 | WordPress Unlimited Elements For Elementor plugin <= 1.5.65 - Multiple Broken Access Control vulnerability | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | High | 8.3 | 2024-06-09 09:27:47 | Deep Dive |
| CVE-2024-5329 | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.109 - Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameter | unitecms | Unlimited Elements For Elementor | High | 8.8 | 2024-06-06 09:34:02 | Deep Dive |
| CVE-2024-35674 | WordPress Unlimited Elements For Elementor plugin <= 1.5.109 - Broken Access Control vulnerability | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Medium | 4.3 | 2024-06-05 16:19:34 | Deep Dive |
| CVE-2023-33930 | WordPress Unlimited Elements For Elementor plugin <= 1.5.66 - Unrestricted Zip Extraction vulnerability | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Critical | 9.1 | 2024-06-04 07:08:04 | Deep Dive |
| CVE-2024-5348 | Elements For Elementor <= 2.1 - Authenticated (Contributor+) Local File Inclusion via Multiple Widget Attributes | nicdark | Elements For Elementor | High | 8.8 | 2024-06-01 08:38:57 | Deep Dive |
| CVE-2024-3190 | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.107 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Field | unitecms | Unlimited Elements For Elementor | Medium | 5.4 | 2024-05-30 03:34:28 | Deep Dive |
| CVE-2023-6743 | Unlimited Elements for Elementor <= 1.5.89 - Authenticated(Contributor+) Remote Code Execution via template import | unitecms | Unlimited Elements For Elementor | High | 8.8 | 2024-05-29 04:30:14 | Deep Dive |
| CVE-2024-4779 | Unlimited Elements for Elementor <= 1.5.107 - Authenticated (Contributor+) SQL Injection via data[post_ids][0] | unitecms | Unlimited Elements For Elementor | High | 8.8 | 2024-05-23 09:32:33 | Deep Dive |
| CVE-2024-5177 | Hash Elements <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via url Parameter in Multiple Widgets | hashthemes | Hash Elements | Medium | 6.4 | 2024-05-23 05:32:16 | Deep Dive |