Vulnerabilities > Brizy > Brizy > 2.5.2

DATE CVE VULNERABILITY TITLE RISK
2025-02-12 CVE-2024-10322 Cross-site Scripting vulnerability in Brizy
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping.
network
low complexity
brizy CWE-79
5.4
2025-02-12 CVE-2024-10960 Unrestricted Upload of File with Dangerous Type vulnerability in Brizy
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4.
network
low complexity
brizy CWE-434
8.8