Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Brizy

First CVE: Oct 14, 2021Active for: 5 yearsTotal CVEs: 32
24.7
VTI Score
Low

Brizy is a page-building and website creation platform whose vulnerability footprint, while concentrated in a narrow product line, occupies a prominent niche given the ubiquity of website-builder tools in content management and business web deployment. The recurring disclosures center on web-application layer weaknesses including cross-site scripting, missing authorization controls, unrestricted file uploads, cross-site request forgery, and path traversal, reflecting the input-handling and access-control demands inherent to systems that accept and render user-generated content and administrative configuration. These weakness classes are characteristic of page-builder and plugin architectures where template handling, file management, and privilege boundaries become attack vectors. Defenders deploying Brizy or its derivatives should prioritize input-validation and authorization mechanisms, particularly around file upload and administrative interfaces, as these recur in the vendor's advisory history. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
2.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Brizy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 14, 2021
4 years ago
Most Recent CVE
Jul 29, 2025
360 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-2219HIGH
The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Jul 25, 20227.234NOYES
CVE-2021-38346HIGH
The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot A
Oct 14, 20218.828NONO
CVE-2024-10960HIGH
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and
Feb 12, 20258.825NONO
CVE-2024-1311HIGH
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and inc
Mar 13, 20248.825NONO
CVE-2025-26902HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Brizy Brizy Pro allows Cross Site Request Forgery.This issue affects Brizy Pro: from n/a through 2.6.1.
Apr 9, 20258.824NONO
CVE-2025-26901HIGH
Missing Authorization vulnerability in Brizy Brizy Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy Pro: from n/a through 2.6.1.
Apr 9, 20258.824NONO
CVE-2020-36714HIGH
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.12
Oct 20, 20238.123NONO
CVE-2021-38345MEDIUM
The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modi
Oct 14, 20216.523NONO
CVE-2024-3242HIGH
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageContent function called via store
Jul 18, 20248.822NONO
CVE-2024-1937MEDIUM
The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_item' function in all versions up
Jul 16, 20246.521NONO
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
75%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network32 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (43.8%)
Unknown0 (0.0%)
Required18 (56.3%)
Privileges Required
Low24 (75.0%)
High0 (0.0%)
None8 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.1% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Brizy.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Brizy — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Brizy's Products

View all 3 CNAs →

Top CWEs