Brizy is a page-building and website creation platform whose vulnerability footprint, while concentrated in a narrow product line, occupies a prominent niche given the ubiquity of website-builder tools in content management and business web deployment. The recurring disclosures center on web-application layer weaknesses including cross-site scripting, missing authorization controls, unrestricted file uploads, cross-site request forgery, and path traversal, reflecting the input-handling and access-control demands inherent to systems that accept and render user-generated content and administrative configuration. These weakness classes are characteristic of page-builder and plugin architectures where template handling, file management, and privilege boundaries become attack vectors. Defenders deploying Brizy or its derivatives should prioritize input-validation and authorization mechanisms, particularly around file upload and administrative interfaces, as these recur in the vendor's advisory history. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Brizy over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2219HIGH The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | Jul 25, 2022 | 7.2 | 34 | NO | YES |
CVE-2021-38346HIGH The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot A | Oct 14, 2021 | 8.8 | 28 | NO | NO |
CVE-2024-10960HIGH The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and | Feb 12, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-1311HIGH The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and inc | Mar 13, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-26902HIGH Cross-Site Request Forgery (CSRF) vulnerability in Brizy Brizy Pro allows Cross Site Request Forgery.This issue affects Brizy Pro: from n/a through 2.6.1. | Apr 9, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-26901HIGH Missing Authorization vulnerability in Brizy Brizy Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy Pro: from n/a through 2.6.1. | Apr 9, 2025 | 8.8 | 24 | NO | NO |
CVE-2020-36714HIGH The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.12 | Oct 20, 2023 | 8.1 | 23 | NO | NO |
CVE-2021-38345MEDIUM The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modi | Oct 14, 2021 | 6.5 | 23 | NO | NO |
CVE-2024-3242HIGH The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageContent function called via store | Jul 18, 2024 | 8.8 | 22 | NO | NO |
CVE-2024-1937MEDIUM The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_item' function in all versions up | Jul 16, 2024 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brizy.
Media articles that mention a CVE ID that affects a product developed by Brizy — matched by CVE ID, not by vendor name.