Templately
Templately: vulnerabilidades y CVE
Templately tiene 6 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-66667 | Alta (7.1) | 0.25% | — | 18 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. |
| CVE-2026-18438 | Alta (8.8) | 1.3% | — | 15 ago 2026 | The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the… |
| CVE-2026-15359 | Media (6.5) | 0.34% | — | 7 ago 2026 | The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with… |
| CVE-2026-0831 | Media (5.3) | 0.27% | — | 10 ene 2026 | The Templately plugin for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 3.4.8. This is due to inadequate input validation in the `save_template_to_file()` function where… |
| CVE-2024-47308 | Crítica (9.8) | 1.7% | — | 1 nov 2024 | Missing Authorization vulnerability in WPDeveloper Templately templately.This issue affects Templately: from n/a through <= 3.1.2. |
| CVE-2023-5454 | Alta (7.5) | 0.61% | — | 6 nov 2023 | The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts. |