Vulnerabilities > Brizy

DATE CVE VULNERABILITY TITLE RISK
2023-12-29 CVE-2023-51396 Cross-site Scripting vulnerability in Brizy Brizy-Page Builder
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brizy.Io Brizy – Page Builder allows Stored XSS.This issue affects Brizy – Page Builder: from n/a through 2.4.29.
network
low complexity
brizy CWE-79
5.4
2023-10-20 CVE-2020-36714 Incorrect Authorization vulnerability in Brizy Brizy-Page Builder
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125.
network
low complexity
brizy CWE-863
8.1
2023-06-09 CVE-2023-2897 Insufficient Verification of Data Authenticity vulnerability in Brizy
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18.
network
low complexity
brizy CWE-345
5.3
2022-06-27 CVE-2022-2040 Cross-site Scripting vulnerability in Brizy Brizy-Page Builder
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
network
brizy CWE-79
3.5
2022-06-27 CVE-2022-2041 Cross-site Scripting vulnerability in Brizy Brizy-Page Builder
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
network
brizy CWE-79
3.5
2021-10-14 CVE-2021-38344 Cross-site Scripting vulnerability in Brizy Brizy-Page Builder
The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers.
network
brizy CWE-79
3.5
2021-10-14 CVE-2021-38345 Incorrect Authorization vulnerability in Brizy Brizy-Page Builder
The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor.
network
low complexity
brizy CWE-863
6.5
2021-10-14 CVE-2021-38346 Unrestricted Upload of File with Dangerous Type vulnerability in Brizy Brizy-Page Builder
The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot AJAX action.
network
low complexity
brizy CWE-434
6.5