Envato's disclosures center on web-based creative marketplace and templating products, with the durable signal clustered around Complete Gallery Manager and related template-management plugins. The observed weakness classes span cross-site scripting, unrestricted file uploads, and related input-handling issues characteristic of web-facing asset and content-management surfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Envato over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-5962MEDIUM Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arb | Sep 30, 2013 | 5.1 | 29 | NO | YES |
CVE-2021-4330HIGH The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads due to insufficient validation of file type upon extracting | Mar 7, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-37550MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Envato Template Kit – Export allows Stored XSS.This issue affects Templ | Jul 21, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-56275MEDIUM Server-Side Request Forgery (SSRF) vulnerability in Envato Envato Elements allows Server Side Request Forgery.This issue affects Envato Elements: from n/a through 2.0.14. | Jan 7, 2025 | 4.1 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Envato.
Media articles that mention a CVE ID that affects a product developed by Envato — matched by CVE ID, not by vendor name.