Vulnerabilities > Brizy

DATE CVE VULNERABILITY TITLE RISK
2024-03-13 CVE-2024-1291 Cross-site Scripting vulnerability in Brizy
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL parameter in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping.
network
low complexity
brizy CWE-79
5.4
2024-03-13 CVE-2024-1293 Cross-site Scripting vulnerability in Brizy
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media custom block in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping.
network
low complexity
brizy CWE-79
5.4
2024-03-13 CVE-2024-1296 Cross-site Scripting vulnerability in Brizy
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
brizy CWE-79
5.4
2024-02-26 CVE-2024-1165 Path Traversal vulnerability in Brizy
The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'.
network
low complexity
brizy CWE-22
6.5
2023-12-29 CVE-2023-51396 Cross-site Scripting vulnerability in Brizy
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brizy.Io Brizy – Page Builder allows Stored XSS.This issue affects Brizy – Page Builder: from n/a through 2.4.29.
network
low complexity
brizy CWE-79
5.4
2023-10-20 CVE-2020-36714 Incorrect Authorization vulnerability in Brizy
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125.
network
low complexity
brizy CWE-863
8.1
2023-06-09 CVE-2023-2897 Insufficient Verification of Data Authenticity vulnerability in Brizy
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18.
network
low complexity
brizy CWE-345
5.3
2022-07-25 CVE-2022-2219 Unspecified vulnerability in Brizy Unyson
The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
network
low complexity
brizy
7.2
2022-06-27 CVE-2022-2040 Cross-site Scripting vulnerability in Brizy
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
network
low complexity
brizy CWE-79
5.4
2022-06-27 CVE-2022-2041 Cross-site Scripting vulnerability in Brizy
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
network
low complexity
brizy CWE-79
5.4