Avada is a web-application and page-builder platform with a narrowly focused product portfolio centered on its Fusion Builder component. The vendor's durable signal reflects typical web-application weaknesses: cross-site request forgery and SQL injection vulnerabilities, which are recurrent input-handling and state-management concerns in content-management and templating contexts.
The number and severity of CVEs published that impact products developed by Avada over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39309HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through | Mar 28, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-39311HIGH Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1. | Mar 27, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Avada.
Media articles that mention a CVE ID that affects a product developed by Avada — matched by CVE ID, not by vendor name.