Extension WordPress
Vulnérabilités Colibri Page Builder
Cette page rassemble les failles publiées pour Colibri Page Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Colibri Page Builder
19 fiches
Colibri Page Builder <= 1.0.345 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-1.0.345
1.0.358
18/12/2025
Colibri Page Builder <= 1.0.335 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-1.0.335
1.0.342
12/12/2025
Colibri Page Builder <= 1.0.334 – Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_newsletter Shortcode
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-1.0.334
1.0.335
10/10/2025
Colibri Page Builder < 1.0.334 – Authenticated (Shop manager+) Stored Cross-Site Scripting
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.0.334 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and…
[*, 1.0.334)
1.0.334
22/09/2025
Colibri Page Builder <= 1.0.319 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.319 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.0.319
1.0.332
04/04/2025
Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-1.0.286
1.0.288
03/12/2024
Colibri Page Builder <= 1.0.276 – Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player Shortcode
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-1.0.276
1.0.277
06/06/2024
Colibri Page Builder <= 1.0.276 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-1.0.276
1.0.277
05/06/2024
Colibri Page Builder <= 1.0.272 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri-gallery-slideshow' Shortcode
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gallery-slideshow' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-1.0.272
1.0.274
22/04/2024
Colibri Page Builder <= 1.0.272 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri_breadcrumb_element' Shortcode
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_breadcrumb_element' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-1.0.272
1.0.274
22/04/2024
Colibri Page Builder <= 1.0.262 – Authenticated (Author+) Stored Cross-Site Scripting
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter in all versions up to, and including, 1.0.262 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.0.262
1.0.264
22/04/2024
Colibri Page Builder <= 1.0.263 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_post_title' shortcode in all versions up to, and including, 1.0.263 due to insufficient input sanitization and output escaping on user supplied attributes…
*-1.0.263
1.0.270
01/04/2024
Colibri Page Builder <= 1.0.248 – Missing Authorization
The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_colibri_page_builder_wpmu_setting AJAX action in all versions up to, and including, 1.0.248. This makes it possible for…
*-1.0.248
1.0.249
26/03/2024
Colibri Page Builder <= 1.0.260 – Missing Authorization
The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated…
*-1.0.260
1.0.263
08/03/2024
Colibri Page Builder <= 1.0.253 – Cross-Site Request Fogery via cp_shortcode_refresh
The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the cp_shortcode_refresh() function. This makes it possible…
*-1.0.253
1.0.260
22/02/2024
Colibri Page Builder <= 1.0.253 – Cross-Site Request Fogery via extend_builder
The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the apiCall() function. This makes it possible…
*-1.0.253
1.0.260
22/02/2024
Colibri Page Builder <= 1.0.239 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_builder_render_js shortcode in all versions up to, and including, 1.0.239 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-1.0.239
1.0.240
23/12/2023
Colibri Page Builder <= 1.0.240 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0.240 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level…
*-1.0.240
1.0.241
19/12/2023
Colibri Page Builder <= 1.0.227 – Authenticated (Administrator+) SQL Injection via post_id
The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.0.227 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
*-1.0.227
1.0.229
22/06/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.