Extendthemes
Extendthemes Colibri Page Builder: vulnerabilidades y CVE
Extendthemes Colibri Page Builder tiene 18 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses4
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-11747 | Media (6.4) | 0.29% | — | 19 dic 2025 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and… |
| CVE-2025-11376 | Media (6.4) | 0.22% | — | 13 dic 2025 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization… |
| CVE-2025-59593 | Media (5.9) | 0.22% | — | 22 oct 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder colibri-page-builder allows Stored XSS.This issue affects Colibri Page Builder:… |
| CVE-2025-9560 | Media (6.4) | 0.23% | — | 11 oct 2025 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input… |
| CVE-2025-32185 | Media (5.4) | 0.40% | — | 4 abr 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder colibri-page-builder allows Stored XSS.This issue affects Colibri Page Builder:… |
| CVE-2024-4451 | Media (5.4) | 0.26% | — | 7 jun 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, 1.0.276 due to insufficient input… |
| CVE-2024-5038 | Media (5.4) | 0.32% | — | 6 jun 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output… |
| CVE-2024-3340 | Media (5.4) | 0.45% | — | 2 may 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gallery-slideshow' shortcode in all versions up to, and including, 1.0.272 due to insufficient input… |
| CVE-2024-3338 | Media (5.4) | 0.42% | — | 2 may 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter in all versions up to, and including, 1.0.262 due to insufficient input sanitization and output… |
| CVE-2024-3337 | Media (5.4) | 0.42% | — | 2 may 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_breadcrumb_element' shortcode in all versions up to, and including, 1.0.272 due to insufficient input… |
| CVE-2024-2839 | Media (5.4) | 0.32% | — | 2 abr 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_post_title' shortcode in all versions up to, and including, 1.0.263 due to insufficient input… |
| CVE-2024-28004 | Media (4.3) | 0.36% | — | 28 mar 2024 | Missing Authorization vulnerability in ExtendThemes Colibri Page Builder.This issue affects Colibri Page Builder: from n/a through 1.0.248. |
| CVE-2024-1870 | Media (4.3) | 0.41% | — | 9 mar 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including,… |
| CVE-2024-1362 | Media (4.3) | 0.21% | — | 23 feb 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the cp_shortcode_refresh()… |
| CVE-2024-1361 | Media (4.3) | 0.21% | — | 23 feb 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the apiCall() function.… |
| CVE-2023-6988 | Media (5.4) | 0.37% | — | 11 ene 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_builder_render_js shortcode in all versions up to, and including, 1.0.239 due to insufficient input… |
| CVE-2023-50833 | Media (5.4) | 0.37% | — | 21 dic 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExtendThemes Colibri Page Builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through 1.0.239. |
| CVE-2023-2188 | Media (4.9) | 0.85% | — | 31 ago 2023 | The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.0.227 due to insufficient escaping on the user supplied parameter and lack of… |