Vulnerabilities > Extendthemes > Colibri Page Builder > 1.0.276

DATE CVE VULNERABILITY TITLE RISK
2024-06-07 CVE-2024-4451 Cross-site Scripting vulnerability in Extendthemes Colibri Page Builder
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
extendthemes CWE-79
5.4
2024-06-06 CVE-2024-5038 Cross-site Scripting vulnerability in Extendthemes Colibri Page Builder
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
extendthemes CWE-79
5.4