Qi Blocks

22 known CVEs 60K+ active installs

Scan My Site Free

UNKNOWN: 22
Known Vulnerabilities 22
CVE-2025-12182 UNKNOWN EPSS 0.1%
Published 2025-11-15 · Affected: *
The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up to, and including, 1.4.3. This is
CVE-2025-12180 UNKNOWN EPSS 0.1%
Published 2025-11-01 · Affected: *
The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin storing arbitrary CSS styles submitted via the `qi-bloc
CVE-2025-1627 UNKNOWN EPSS 0.1%
Published 2025-05-19 · Affected: *
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the c
CVE-2025-1627 UNKNOWN EPSS 0.1%
Published 2025-05-19 · Affected: *
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the c
CVE-2025-1626 UNKNOWN EPSS 0.1%
Published 2025-05-19 · Affected: *
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users
CVE-2025-1626 UNKNOWN EPSS 0.1%
Published 2025-05-19 · Affected: *
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users
CVE-2025-1625 UNKNOWN EPSS 0.2%
Published 2025-05-19 · Affected: *
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users wi
CVE-2025-1625 UNKNOWN EPSS 0.2%
Published 2025-05-19 · Affected: *
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users wi
CVE-2024-49690 UNKNOWN EPSS 0.4%
Published 2024-10-23 · Affected: *
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-49690 UNKNOWN EPSS 0.4%
Published 2024-10-23 · Affected: *
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-49690 UNKNOWN EPSS 0.4%
Published 2024-10-23 · Affected: *
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-49690 UNKNOWN EPSS 0.4%
Published 2024-10-23 · Affected: *
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-49690 UNKNOWN EPSS 0.4%
Published 2024-10-23 · Affected: *
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-49690 UNKNOWN EPSS 0.4%
Published 2024-10-23 · Affected: *
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-38712 UNKNOWN EPSS 0.2%
Published 2024-07-20 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-38712 UNKNOWN EPSS 0.2%
Published 2024-07-20 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-38712 UNKNOWN EPSS 0.2%
Published 2024-07-20 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-38712 UNKNOWN EPSS 0.2%
Published 2024-07-20 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-38712 UNKNOWN EPSS 0.2%
Published 2024-07-20 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-38712 UNKNOWN EPSS 0.2%
Published 2024-07-20 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.
CVE-2024-5221 UNKNOWN EPSS 0.2%
Published 2024-06-06 · Affected: *
The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 1.2.9 due to insufficient input sanitization and ou
CVE-2024-5221 UNKNOWN EPSS 0.2%
Published 2024-06-06 · Affected: *
The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 1.2.9 due to insufficient input sanitization and ou

Is Qi Blocks running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free