Vulnerabilities > Envato

DATE CVE VULNERABILITY TITLE RISK
2024-07-21 CVE-2024-37550 Unspecified vulnerability in Envato Template KIT - Export
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Envato Template Kit – Export allows Stored XSS.This issue affects Template Kit – Export: from n/a through 1.0.22.
network
low complexity
envato
4.8
2023-03-07 CVE-2021-4330 Unspecified vulnerability in Envato Elements and Template KIT - Import
The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads due to insufficient validation of file type upon extracting uploaded Zip files in the installFreeTemplateKit and uploadTemplateKitZipFile functions.
network
low complexity
envato
8.8