Home/Product/brizy
Product

brizy

32 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-4370
< 2.6.21
The Brizy - Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_extern
5.3MEDIUM
CVE-2025-32198
<= 2.6.14
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy brizy.Thi
6.5MEDIUM
CVE-2025-26902
<= 2.6.1
Cross-Site Request Forgery (CSRF) vulnerability in Brizy Pro allows Cross Site Request Forgery.This issue affects Brizy Pro:
4.3MEDIUM
CVE-2025-26901
<= 2.6.1
Missing Authorization vulnerability in Brizy Pro allows Exploiting Incorrectly Configured Access Control Security Levels.Thi
4.3MEDIUM
CVE-2024-10322
< 2.6.9
The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all ve
6.4MEDIUM
CVE-2024-10960
< 2.6.5
The Brizy - Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '
9.9CRITICAL
CVE-2025-22763
<= 2.6.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Brizy Pro allows Re
7.1HIGH
CVE-2024-6254
< 2.5.2
The Brizy - Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.
4.3MEDIUM
CVE-2024-3242
< 2.4.45
The Brizy - Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in
8.8HIGH
CVE-2024-1937
< 2.4.45
The Brizy - Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
7.1HIGH
CVE-2024-1164
< 2.4.44
The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget er
6.4MEDIUM
CVE-2024-3667
< 2.4.44
The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of multiple wid
7.4HIGH
CVE-2024-2087
< 2.4.44
The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in all version
7.2HIGH
CVE-2024-1940
< 2.4.42
The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versions up to,
7.1HIGH
CVE-2024-1161
< 2.4.44
The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for
6.4MEDIUM
CVE-2024-3711
< 2.4.44
The Brizy - Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capability chec
4.3MEDIUM
CVE-2024-34814
< 2.7.31
Cross-Site Request Forgery (CSRF) vulnerability in Unyson unyson.This issue affects Unyson: from n/a through <= 2.7.29.
5.4MEDIUM
CVE-2023-44472
<= 2.7.28
Missing Authorization vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.28.
4.3MEDIUM
CVE-2024-1311
< 2.4.41
The Brizy - Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the s
8.8HIGH
CVE-2024-1296
< 2.4.41
The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload in all ve
6.4MEDIUM
CVE-2024-1293
< 2.4.41
The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media custom block in
6.4MEDIUM
CVE-2024-1291
< 2.4.41
The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL parameter in all
6.4MEDIUM
CVE-2024-1165
< 2.4.40
The Brizy - Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 vi
4.3MEDIUM
CVE-2023-51396
<= 2.4.29
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brizy.Io Brizy - Page Builde
6.5MEDIUM
CVE-2020-36714
<= 1.0.125
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator()
7.4HIGH
CVE-2023-2897
<= 2.4.18
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is
3.7LOW
CVE-2022-2219
< 2.7.27
The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading
7.2HIGH
CVE-2022-2041
< 2.4.2
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as
5.4MEDIUM
CVE-2022-2040
< 2.4.2
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low
5.4MEDIUM
CVE-2021-38346
<= 2.3.11
The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of thei
8.8HIGH
CVE-2021-38345
>= 1.0.127 and <= 2.3.11
The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user access
7.1HIGH
CVE-2021-38344
<= 2.3.11
The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers
6.4MEDIUM
threatengine.sh