Vulnerabilities > Bold Themes > Bold Page Builder
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-12-16 | CVE-2024-54382 | Path Traversal vulnerability in Bold-Themes Bold Page Builder Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldThemes Bold Page Builder allows Path Traversal.This issue affects Bold Page Builder: from n/a through 5.1.5. | 4.9 |
2024-12-06 | CVE-2024-53801 | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 5.2.1. | 5.4 |
2024-11-19 | CVE-2024-50417 | Missing Authorization vulnerability in Bold-Themes Bold Page Builder Missing Authorization vulnerability in BoldThemes Bold Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bold Page Builder: from n/a through 5.1.3. | 8.8 |
2024-10-06 | CVE-2024-47298 | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 5.1.1. | 5.4 |
2024-10-05 | CVE-2024-47391 | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a before 5.1.1. | 5.4 |
2024-04-10 | CVE-2024-2734 | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AI features all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-10 | CVE-2024-2735 | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Price List' element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-10 | CVE-2024-2736 | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tags in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-10 | CVE-2024-2733 | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Separator" element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-3266 | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of widgets in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |