Website Builder
Vendor:
First CVE: Jan 22, 2020 · Active for 6 years
37
Total CVEs
More Total CVEs than 97% of tracked products
6.2
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Website Builder over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2020
6 years ago
Most Recent CVE
Aug 12, 2025
346 days ago
CVE Severity & Scoring
Website Builder37 CVEs
84%
11%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network37 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (29.7%)
Unknown0 (0.0%)
Required26 (70.3%)
Privileges Required
Low29 (78.4%)
High2 (5.4%)
None6 (16.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1329HIGH The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboa | Apr 19, 2022 | 8.8 | 89 | NO | YES |
CVE-2021-24891MEDIUM The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting | Nov 23, 2021 | 6.1 | 44 | NO | YES |
CVE-2022-29455MEDIUM DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions. | Jun 13, 2022 | 6.1 | 41 | NO | YES |
CVE-2023-48777HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1. | Mar 26, 2024 | 8.8 | 40 | NO | YES |
CVE-2023-47504CRITICAL Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Bu | Apr 24, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-47505MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects E | Nov 30, 2023 | 5.4 | 29 | NO | NO |
CVE-2022-4953MEDIUM The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that | Aug 14, 2023 | 6.1 | 28 | NO | YES |
CVE-2023-0329HIGH The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, | May 30, 2023 | 7.2 | 26 | NO | NO |
CVE-2020-7109CRITICAL The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. | Jan 22, 2020 | 9.8 | 26 | NO | NO |
CVE-2024-24934HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Cal | May 17, 2024 | 8.1 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (37 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.7% of CVEs· 96th percentile
Nuclei
4 CVEs
10.8% of CVEs· 97th percentile
ExploitDB
1 CVE
2.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (37 CVEs).
Media Mentions
Signals from CVEs in this product scope (37 CVEs).
Top CNAs Publishing CVEs For Website Builder
Top CWEs
Versions
No cataloged versions.