Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Brizy – Page Builder — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in Brizy – Page Builder, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses in Brizy, a WordPress page builder plugin, categorized by the Common Weakness Enumeration (CWE) framework. It aggregates vulnerability records associated with this specific product to provide a centralized resource for security researchers, developers, and website administrators. The collection includes issues reported between January 2018 and the present day, covering a comprehensive timeline of the plugin’s security history. Users visiting this page can track vendor advisories to understand how the developer has responded to various security incidents over time. Additionally, individuals can analyze the prevalence of specific weakness classes within this tool to better assess risk profiles. This resource also allows users to look up the complete vulnerability history of Brizy, offering insights into past security flaws and their resolutions. By consolidating these data points, the page facilitates deeper analysis of software stability and coding practices in popular WordPress extensions. The information is derived from public vulnerability databases, bug bounty reports, and official security advisories. This structured approach helps stakeholders evaluate the overall security posture of the product without requiring them to scour multiple disparate sources. The content is organized to support both high-level overviews and detailed technical reviews. Whether you are auditing your own installations or researching common attack vectors, this aggregation serves as a factual reference point. It emphasizes transparency and accuracy in reporting software defects. All entries are verified for relevance and linked to appropriate identifiers where available. This ensures that users can trust the information presented here for decision-making purposes related to software maintenance and security hardening.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-5324 Brizy – Page Builder <= 2.8.11 - Unauthenticated Stored Cross-Site Scripting via FileUpload Field Value CWE-79 7.2 High2026-05-02
CVE-2025-0969 Brizy – Page Builder <= 2.7.16 - Authenticated (Contributor+) Sensitive Information Exposure via get_users Function CWE-359 6.5 Medium2025-12-13
CVE-2025-4370 Brizy <= 2.6.20 - Missing Authorization to Unauthenticated Limited File Upload CWE-862 5.3 Medium2025-07-29
CVE-2024-10322 Brizy – Page Builder <= 2.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload CWE-79 6.4 Medium2025-02-12
CVE-2024-10960 Brizy – Page Builder <= 2.6.4 - Authenticated (Contributor+) Arbitrary File Upload via storeUploads CWE-434 9.9 Critical2025-02-12
CVE-2024-6254 Brizy – Page Builder <= 2.5.1 - Cross-Site Request Forgery CWE-20 4.3 Medium2024-08-08
CVE-2024-3242 Brizy – Page Builder <= 2.4.44 - Authenticated (Contributor+) Arbitrary File Upload CWE-434 8.8 High2024-07-18
CVE-2024-1937 Brizy – Page Builder <= 2.4.44 - Missing Authorization to Authenticated (Contributor+) Post Modification CWE-862 7.1 High2024-07-16
CVE-2024-1164 Brizy – Page Builder <= 2.4.43 - Authenticated(Contributor+) Stored Cross-Site Scripting via Form Functionality CWE-79 6.4 Medium2024-06-05
CVE-2024-3667 Brizy – Page Builder <= 2.4.43 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget Link To URL CWE-79 7.4 High2024-06-05
CVE-2024-1940 Brizy – Page Builder <= 2.4.41 - Authenticated(Contributor+) Stored Cross-Site Scripting CWE-79 7.1 High2024-06-05
CVE-2024-2087 Brizy – Page Builder <= 2.4.43 - Unauthenticated Stored Cross-Site Scripting via Form CWE-79 7.2 High2024-06-05
CVE-2024-1161 Brizy – Page Builder <= 2.4.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes CWE-79 6.4 Medium2024-06-05
CVE-2024-3711 Brizy – Page Builder <= 2.4.43 - Missing Authorization CWE-862 4.3 Medium2024-05-23
CVE-2024-1291 Brizy – Page Builder <= 2.4.40 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-03-13
CVE-2024-1311 Brizy – Page Builder <= 2.4.40 - Authenticated (Contributor+) Arbitrary File Upload CWE-434 8.8 High2024-03-13
CVE-2024-1293 Brizy – Page Builder <= 2.4.40 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-03-13
CVE-2024-1296 Brizy – Page Builder <= 2.4.40 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-03-13
CVE-2024-1165 Brizy – Page Builder <= 2.4.39 - Authenticated (Contributor+) Directory Traversal CWE-22 4.3 Medium2024-02-24
CVE-2023-51396 WordPress Brizy – Page Builder Plugin <= 2.4.29 is vulnerable to Cross Site Scripting (XSS) CWE-79 6.5 Medium2023-12-29
CVE-2020-36714 Brizy < 1.0.126 - Authorization Bypass to Settings Updates CWE-285 7.4 High2023-10-20
CVE-2023-2897 Brizy Page Builder <= 2.4.18 - IP Address Spoofing to Protection Mechanism Bypass CWE-348 3.7 Low2023-06-09
CVE-2022-2041 Brizy Page Builder < 2.4.2 - Contributor+ Stored Cross-Site Scripting via Element Content CWE-79 5.4 -2022-06-27
CVE-2022-2040 Brizy Page Builder < 2.4.2 - Contributor+ Stored Cross-Site Scripting via Element URL CWE-79 5.4 -2022-06-27

All 24 known CVE vulnerabilities affecting Brizy – Page Builder with full Chinese analysis, references, and POCs where available.