Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

BoldGrid — Vulnerabilities & Security Advisories 51

Browse all 51 CVE security advisories affecting BoldGrid. AI-powered Chinese analysis, POCs, and references for each vulnerability.

BoldGrid operates as a WordPress plugin and theme provider, primarily targeting small business owners and agencies seeking an integrated website building solution. Security audits have identified forty-three distinct Common Vulnerabilities and Exposures (CVEs) associated with its software ecosystem. Historically, these flaws predominantly involve Cross-Site Scripting (XSS) and SQL Injection, stemming from insufficient input validation and improper sanitization of user-supplied data. Several incidents also highlight privilege escalation risks, where authenticated users could exploit weak access controls to perform administrative actions. The platform’s architecture, which tightly couples themes with plugins, has occasionally amplified the blast radius of individual vulnerabilities. While no massive data breaches have been publicly confirmed, the high volume of disclosed CVEs indicates a pattern of delayed patching or recurring coding errors in core components. Users are advised to maintain strict update protocols to mitigate these persistent exposure vectors.

Found 14 results / 51 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-18109 W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name — W3 Total Cache CWE-79 7.2 High 2026-08-14
CVE-2026-66695 WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability — W3 Total Cache CWE-35 6.5 Medium 2026-08-06
CVE-2026-9282 W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter — W3 Total Cache CWE-22 7.5 High 2026-07-11
CVE-2026-57623 WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability — W3 Total Cache CWE-1284 9.0 Critical 2026-07-02
CVE-2026-39595 WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability — W3 Total Cache CWE-862 4.7 Medium 2026-06-17
CVE-2026-5032 W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header — W3 Total Cache CWE-200 7.5 High 2026-04-02
CVE-2026-27384 WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability — W3 Total Cache CWE-1284 9.0 Critical 2026-03-05
CVE-2024-12006 W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation — W3 Total Cache CWE-862 5.3 Medium 2025-01-14
CVE-2024-12008 W3 Total Cache <= 2.8.1 Information Exposure via Log Files — W3 Total Cache CWE-200 5.3 Medium 2025-01-14
CVE-2024-12365 W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery — W3 Total Cache CWE-862 8.5 High 2025-01-14
CVE-2023-5359 W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext — W3 Total Cache CWE-200 3.7 Low 2024-09-24
CVE-2021-24452 W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context) — W3 Total Cache CWE-79 6.1 - 2021-07-19
CVE-2021-24436 W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context) — W3 Total Cache CWE-79 6.1 - 2021-07-19
CVE-2021-24427 W3 Total Cache < 2.1.3 - Authenticated Stored XSS — W3 Total Cache CWE-79 4.8 - 2021-07-12

This page lists every published CVE security advisory associated with BoldGrid. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.