Skip to main content

Vendor archive

ideabox CVEs

Beta · best-effort

17 CVEs tagged to vendor ideabox0 Critical, 3 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2024-12239

Published Dec 17, 2024

The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and including, 1.3.0.5…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43330

Published Aug 18, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack for Beaver Builder allows Reflected XSS.Th…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37409

Published Jul 22, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack Lite for Beaver Builder powerpack-addon-for-beave…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37410

Published Jul 9, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in IdeaBox Creations PowerPack Lite for Beaver Builder powerp…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5787

Published Jun 13, 2024

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the pl…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3668

Published Jun 8, 2024

The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5327

Published May 30, 2024

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘pp_animated_gradie…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2492

Published Apr 9, 2024

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Tweet widget in all versions up to, and including, 2.7.18 due…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2289

Published Apr 9, 2024

The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in multiple elements in all versions up to, and including, 1.3…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2491

Published Mar 30, 2024

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the *_html_tag* attribute of multiple widgets in all versions up to, and i…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1411

Published Feb 29, 2024

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings of the Twitter Buttons Widget in all versions up to, and incl…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1055

Published Feb 7, 2024

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's buttons in all versi…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6984

Published Jan 3, 2024

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-49739

Published Dec 14, 2023

Vulnerability in IdeaBox Creations PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a through 2.9.23.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-0176

Published Feb 14, 2022

The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Refle…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25027

Published Jan 3, 2022

The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a R…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24263

Published May 5, 2021

The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1