Website Builder

Vendor:

First CVE: Jan 22, 2020 · Active for 6 years

37
Total CVEs
More Total CVEs than 97% of tracked products
6.2
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Website Builder over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2020
6 years ago
Most Recent CVE
Aug 12, 2025
346 days ago

CVE Severity & Scoring

Website Builder37 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network37 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (29.7%)
Unknown0 (0.0%)
Required26 (70.3%)
Privileges Required
Low29 (78.4%)
High2 (5.4%)
None6 (16.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboa
Apr 19, 20228.889NOYES
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting
Nov 23, 20216.144NOYES
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
Jun 13, 20226.141NOYES
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.
Mar 26, 20248.840NOYES
Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Bu
Apr 24, 20249.829NONO
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects E
Nov 30, 20235.429NONO
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that
Aug 14, 20236.128NOYES
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement,
May 30, 20237.226NONO
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
Jan 22, 20209.826NONO
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Cal
May 17, 20248.123NONO

Exploit Exposure

Signals from CVEs in this product scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.7% of CVEs· 96th percentile
Nuclei
4 CVEs
10.8% of CVEs· 97th percentile
ExploitDB
1 CVE
2.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (37 CVEs).

Media Mentions

Signals from CVEs in this product scope (37 CVEs).

Top CNAs Publishing CVEs For Website Builder

Top CWEs

Versions

No cataloged versions.