Extension WordPress
Vulnérabilités Gutenberg
Cette page rassemble les failles publiées pour Gutenberg, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Gutenberg
6 fiches
Gutenberg <= 21.8.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 21.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-21.8.2
21.9.0
25/10/2025
WordPress Core < 6.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block
WordPress Core is vulnerable to Stored Cross-Site Scripting via the Template Part Block in various versions up to 6.5.5 due to insufficient input sanitization and output escaping on the 'tagName' attributes. This makes it possible for authenticated attackers,…
*-18.6.0
18.6.1
24/06/2024
Gutenberg 12.9.0 – 18.0.0 – Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block
The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in versions 12.9.0 to 18.0.0 due to insufficient output escaping on the display name. This makes it possible for…
12.9.0-18.0.0
18.01
09/04/2024
WordPress Core 5.9-6.3.1 – Authenticated(Contributor+) Stored Cross-Site Scripting via Navigation Attributes
WordPress Core is vulnerable to Stored Cross-Site Scripting via the arrow navigation block attributes in versions between 5.9 and 6.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level privileges…
*-16.8.0
16.8.1
12/10/2023
WordPress Core < 6.0.3 & Gutenberg < 14.3.1 – Authenticated Cross-Site Scripting in Various Blocks
WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to Stored Cross-Site Scripting due to insufficient output escaping on user supplied input. The RSS widget, Search Block,…
*-14.3.0
14.3.1
18/10/2022
WordPress Core < 5.9.2 & Gutenberg < 12.7.2 – Prototype Pollution via Block Editor
WordPress Core in various versions < 5.9.2 and Gutenberg versions less than 12.7.2 are vulnerable to prototype pollution via the block editor which could make injecting malicious web scripts possible in some cases.
[*, 12.7.2)
12.7.2
11/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.