VYPR

Vendor CVEs

Elementor

All CVEs

54 total · sorted by risk
  • CVE-2024-5416MedSep 11, 2024
    risk 0.28cvss 5.4epss 0.00

    The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on…

  • CVE-2023-33922MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2.

  • CVE-2025-8081MedAug 12, 2025
    risk 0.25cvss 4.9epss 0.01

    The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with…

  • CVE-2018-8729MedMar 15, 2018
    risk 0.03cvss 6.1epss 0.07

    Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped.

Page 2 of 2