Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Colorlib

First CVE: Feb 17, 2015Active for: 11 yearsTotal CVEs: 10
25.1
VTI Score
Low

Colorlib develops a modest portfolio of WordPress themes and plugins, primarily including design and functionality extensions such as Activello, Fancybox, Bonkers, and Illdy that are distributed to a broad audience of website builders. The recurring vulnerability profile centers on web-application input-handling and authorization issues—cross-site scripting, code injection, improper access control, and missing authorization—which are endemic to themes and plugins that process user content and interact with WordPress permission models, and the vendor's disclosures have an elevated tendency toward public exploit availability. Defenders should treat Colorlib theme and plugin updates as routine security maintenance for WordPress deployments; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Colorlib over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 17, 2015
11 years ago
Most Recent CVE
Jun 3, 2025
416 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-36708CRITICAL
The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, All
Jun 7, 20239.874NOYES
CVE-2015-1494MEDIUM
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an m
Feb 17, 20154.323NOYES
CVE-2020-36721MEDIUM
The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_
Jun 7, 20236.520NONO
CVE-2022-45849MEDIUM
Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.
Apr 16, 20235.420NONO
CVE-2022-45358MEDIUM
Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.
Apr 13, 20235.420NONO
CVE-2025-3662MEDIUM
The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a C
Jun 3, 20256.119NONO
CVE-2024-1473MEDIUM
The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.99 via the REST API. This makes
Mar 20, 20245.318NONO
CVE-2024-0662MEDIUM
The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions 3.0.2 to 3.3.3 due to insufficient input sanitization an
Apr 9, 20244.816NONO
CVE-2024-49321MEDIUM
Missing Authorization vulnerability in colorlibplugins Simple Custom Post Order simple-custom-post-order allows Exploiting Incorrectly Configured Access Control Security Levels.Thi
Oct 21, 20244.315NONO
CVE-2022-1945MEDIUM
The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Sto
Jun 20, 20224.815NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
90%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network9 (90.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High0 (0.0%)
Unknown1 (10.0%)
User Interaction
None4 (40.0%)
Unknown1 (10.0%)
Required5 (50.0%)
Privileges Required
Low3 (30.0%)
High2 (20.0%)
None4 (40.0%)
Unknown1 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 96th percentile
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Colorlib.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Colorlib — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Colorlib's Products

View all 4 CNAs →

Top CWEs