Brizy – Page Builder

40 known CVEs 70K+ active installs

Scan My Site Free

UNKNOWN: 40
Known Vulnerabilities 40
CVE-2025-32198 UNKNOWN EPSS 0.2%
Published 2025-04-10 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy brizy.This issue affects Brizy: from n/a through <= 2.7.7.
CVE-2025-32198 UNKNOWN EPSS 0.2%
Published 2025-04-10 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy brizy.This issue affects Brizy: from n/a through <= 2.7.7.
CVE-2025-32198 UNKNOWN EPSS 0.2%
Published 2025-04-10 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy brizy.This issue affects Brizy: from n/a through <= 2.7.7.
CVE-2025-32198 UNKNOWN EPSS 0.2%
Published 2025-04-10 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy brizy.This issue affects Brizy: from n/a through <= 2.7.7.
CVE-2025-26902 UNKNOWN EPSS 0.1%
Published 2025-04-09 · Affected: *
Cross-Site Request Forgery (CSRF) vulnerability in Brizy Brizy Pro allows Cross Site Request Forgery.This issue affects Brizy Pro: from n/a through 2.6.1.
CVE-2025-26902 UNKNOWN EPSS 0.1%
Published 2025-04-09 · Affected: *
Cross-Site Request Forgery (CSRF) vulnerability in Brizy Brizy Pro allows Cross Site Request Forgery.This issue affects Brizy Pro: from n/a through 2.6.1.
CVE-2025-26901 UNKNOWN EPSS 0.3%
Published 2025-04-09 · Affected: *
Missing Authorization vulnerability in Brizy Brizy Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy Pro: from n/a through 2.6.1.
CVE-2025-26901 UNKNOWN EPSS 0.3%
Published 2025-04-09 · Affected: *
Missing Authorization vulnerability in Brizy Brizy Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy Pro: from n/a through 2.6.1.
CVE-2025-22763 UNKNOWN EPSS 0.1%
Published 2025-01-21 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Brizy Pro allows Reflected XSS. This issue affects Brizy Pro: from n/a through 2.6.1.
CVE-2025-22763 UNKNOWN EPSS 0.1%
Published 2025-01-21 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Brizy Pro allows Reflected XSS. This issue affects Brizy Pro: from n/a through 2.6.1.
CVE-2024-3242 UNKNOWN EPSS 0.6%
Published 2024-07-18 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageContent function called via storeImages in all versio
CVE-2024-3242 UNKNOWN EPSS 0.6%
Published 2024-07-18 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageContent function called via storeImages in all versio
CVE-2024-1937 UNKNOWN EPSS 0.3%
Published 2024-07-16 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_item' function in all versions up to, and including, 2
CVE-2024-1937 UNKNOWN EPSS 0.3%
Published 2024-07-16 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_item' function in all versions up to, and including, 2
CVE-2024-1164 UNKNOWN EPSS 0.2%
Published 2024-06-05 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget error message and redirect URL in all versions up to, and including, 2.4
CVE-2024-1164 UNKNOWN EPSS 0.2%
Published 2024-06-05 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget error message and redirect URL in all versions up to, and including, 2.4
CVE-2024-3667 UNKNOWN EPSS 0.2%
Published 2024-06-05 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of multiple widgets in all versions up to, and including, 2.4.43 due to insufficient
CVE-2024-3667 UNKNOWN EPSS 0.2%
Published 2024-06-05 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of multiple widgets in all versions up to, and including, 2.4.43 due to insufficient
CVE-2024-2087 UNKNOWN EPSS 0.3%
Published 2024-06-05 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in all versions up to, and including, 2.4.43 due to insufficient input sanitization
CVE-2024-2087 UNKNOWN EPSS 0.3%
Published 2024-06-05 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in all versions up to, and including, 2.4.43 due to insufficient input sanitization
CVE-2024-1940 UNKNOWN EPSS 0.2%
Published 2024-06-05 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versions up to, and including, 2.4.41 due to insufficient input sanitization performe
CVE-2024-1940 UNKNOWN EPSS 0.2%
Published 2024-06-05 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versions up to, and including, 2.4.41 due to insufficient input sanitization performe
CVE-2024-1161 UNKNOWN EPSS 0.2%
Published 2024-06-05 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for blocks in all versions up to, and including, 2.4.43 due to insufficien
CVE-2024-1161 UNKNOWN EPSS 0.2%
Published 2024-06-05 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for blocks in all versions up to, and including, 2.4.43 due to insufficien
CVE-2024-3711 UNKNOWN EPSS 0.3%
Published 2024-05-23 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capability check on the functions action_request_disable, action_change_template, and
CVE-2024-3711 UNKNOWN EPSS 0.3%
Published 2024-05-23 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capability check on the functions action_request_disable, action_change_template, and
CVE-2024-1311 UNKNOWN EPSS 0.7%
Published 2024-03-13 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and including, 2.4.40. This
CVE-2024-1311 UNKNOWN EPSS 0.7%
Published 2024-03-13 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and including, 2.4.40. This
CVE-2024-1296 UNKNOWN EPSS 0.4%
Published 2024-03-13 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload in all versions up to, and including, 2.4.40 due to insufficient input sanitiza
CVE-2024-1296 UNKNOWN EPSS 0.4%
Published 2024-03-13 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload in all versions up to, and including, 2.4.40 due to insufficient input sanitiza
CVE-2024-1293 UNKNOWN EPSS 0.3%
Published 2024-03-13 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media custom block in all versions up to, and including, 2.4.40 due to insufficient input sa
CVE-2024-1293 UNKNOWN EPSS 0.3%
Published 2024-03-13 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media custom block in all versions up to, and including, 2.4.40 due to insufficient input sa
CVE-2024-1291 UNKNOWN EPSS 0.3%
Published 2024-03-13 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL parameter in all versions up to, and including, 2.4.40 due to insufficient input saniti
CVE-2024-1291 UNKNOWN EPSS 0.3%
Published 2024-03-13 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL parameter in all versions up to, and including, 2.4.40 due to insufficient input saniti
CVE-2024-1165 UNKNOWN EPSS 0.5%
Published 2024-02-26 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This makes it possible for authenticated attackers, with c
CVE-2024-1165 UNKNOWN EPSS 0.5%
Published 2024-02-26 · Affected: *
The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This makes it possible for authenticated attackers, with c
CVE-2020-36714 UNKNOWN EPSS 0.4%
Published 2023-10-20 · Affected: *
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it pos
CVE-2020-36714 UNKNOWN EPSS 0.4%
Published 2023-10-20 · Affected: *
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it pos
CVE-2023-2897 UNKNOWN EPSS 0.2%
Published 2023-06-09 · Affected: *
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP addresses in an 'X-Forwa
CVE-2023-2897 UNKNOWN EPSS 0.2%
Published 2023-06-09 · Affected: *
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP addresses in an 'X-Forwa

Is Brizy &#8211; Page Builder running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free