Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Blocksy — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Blocksy, with AI-generated Chinese analysis, references, and POCs.

This page catalogues Common Weakness Enumerations associated with the Blocksy product, categorized by vendor and weakness type. It aggregates a comprehensive list of reported security vulnerabilities and defects affecting this specific software ecosystem. The collection spans data from the initial release of Blocksy through recent updates, ensuring a historical perspective on security issues within the platform. Here, users can track vendor advisories to stay informed about official patches and remediation steps. You can also gain a deeper understanding of specific weakness classes that frequently impact the Blocksy architecture, allowing for better risk assessment and mitigation strategies. Furthermore, the resource enables you to look up a product's vulnerability history to identify patterns in how flaws have been introduced and resolved over time. This centralized view supports developers, security analysts, and administrators in maintaining a secure deployment environment. By reviewing these aggregated entries, stakeholders can prioritize updates based on severity and relevance to their specific installation. The page serves as a factual reference for compliance auditing and continuous monitoring of the product's security posture. It is designed to provide clarity on the scope and nature of past incidents without overwhelming the reader with unnecessary technical jargon. This approach facilitates efficient decision-making regarding patch management and security hardening for Blocksy-based websites and applications.

Vendor: creativethemeshq

CVE ID Title CVSS Severity Published
CVE-2026-8365 Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API Field CWE-502 8.8 High 2026-06-09
CVE-2026-2583 Blocksy <= 2.1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via `blocksy_meta` Fields CWE-79 6.4 Medium 2026-03-02
CVE-2025-55713 WordPress Blocksy Theme <= 2.1.6 - Cross Site Scripting (XSS) Vulnerability CWE-79 5.9 Medium 2025-08-14
CVE-2025-47465 WordPress Blocksy theme <= 2.0.97 - Broken Access Control Vulnerability CWE-862 4.9 Medium 2025-05-07
CVE-2024-37469 WordPress Blocksy theme <= 1.9.5 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.4 Medium 2025-01-02
CVE-2024-11420 Blocksy <= 2.0.77 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-12-05
CVE-2024-5439 Blocksy <= 2.0.50 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-20 6.4 Medium 2024-06-05
CVE-2024-4943 Blocksy <= 2.0.46 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-05-21
CVE-2024-4158 Blocksy <= 2.0.42 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-05-09
CVE-2024-3747 Blocksy <= 2.0.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via About Me block CWE-20 6.4 Medium 2024-05-02
CVE-2024-32961 WordPress Blocksy theme <= 2.0.33 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-04-25
CVE-2024-31382 WordPress Blocksy theme <= 2.0.22 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium 2024-04-15
CVE-2024-1767 Blocksy <= 2.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-03-09
CVE-2024-24871 WordPress Blocksy theme <= 2.0.19 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-02-08

All 14 known CVE vulnerabilities affecting Blocksy with full Chinese analysis, references, and POCs where available.