Skip to main content

Vendor/product archive

fastlinemedia / beaver_builder CVEs

Beta · best-effort

31 CVEs tagged to fastlinemedia / beaver_builder0 Critical, 2 High, 29 Medium, 0 Low, 0 Unrated.

CVE-2025-12558

Published Dec 9, 2025

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via the 'get_attachmen…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-12782

Published Dec 4, 2025

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.9.4. This is due to the plugin not p…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-11726

Published Dec 2, 2025

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.9.4. This is due to insufficient ca…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-8427

Published Oct 23, 2025

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 2…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8897

Published Aug 28, 2025

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'fl_builder' parameter in all versions up to, and includi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4102

Published Jun 20, 2025

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_enabled_icons' function i…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11832

Published Dec 13, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JavaScript row settings in all versions up to, and inc…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53797

Published Dec 6, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Stored XSS.T…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50430

Published Nov 19, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Stored XSS.T…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9505

Published Oct 29, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including,…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9049

Published Sep 27, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Group module in all versions up to, and inclu…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43926

Published Aug 29, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7895

Published Aug 29, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all versions up to, and including, 2.8.3.…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37500

Published Jul 21, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Stored XSS.This issue af…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4430

Published May 14, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the photo widget crop attribute in all versions up to, and includ…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3923

Published May 14, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_target parameter in all versions up to, and including, 2…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2925

Published Apr 2, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including,…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30425

Published Mar 29, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows DOM-Based XS…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1080

Published Mar 13, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via the heading tag in all versions up to, and including, 2.7…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1074

Published Mar 13, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the audio widget 'link_url' parameter in all versions up to, and…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1038

Published Mar 13, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via a 'playground.wordpress.net' parameter in all versio…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0897

Published Mar 13, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to, and including, 2.7…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0896

Published Mar 13, 2024

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link parameter in all versions up to, and including, 2…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0871

Published Mar 13, 2024

The Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Icon Widget 'fl_builder_data[node_preview][link]' and 'fl_builder_data[settings][link_…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50889

Published Dec 29, 2023

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder – WordPress Page Builder allows Stored…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2