Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pagelayer

First CVE: Jan 1, 2021Active for: 6 yearsTotal CVEs: 22
15.5
VTI Score
Low

Pagelayer is a page-building and website-creation platform whose vulnerability exposure centers on web-application-layer weaknesses recurrent across its core product. The durable signal reflects the platform's role in user-generated content and form handling, with repeated instances of cross-site scripting, cross-site request forgery, and authorization and input-validation gaps that are characteristic of web builders where user input flows directly into rendering contexts. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
4.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pagelayer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 2021
5 years ago
Most Recent CVE
Apr 8, 2026
107 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-35944HIGH
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.
Jan 1, 20218.826NONO
CVE-2024-30465HIGH
Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through 1.8.1.
Jun 9, 20248.824NONO
CVE-2020-35947HIGH
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed
Jan 1, 20217.423NONO
CVE-2023-4687MEDIUM
The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.
Oct 16, 20236.119NONO
CVE-2020-36384MEDIUM
PageLayer before 1.3.5 allows reflected XSS via color settings.
Jun 7, 20216.119NONO
CVE-2020-36383MEDIUM
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
Jun 7, 20216.119NONO
CVE-2025-24573MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softaculous PageLayer pagelayer allows DOM-Based XSS.This issue affects PageLa
Jan 24, 20256.518NONO
CVE-2024-2504MEDIUM
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and in
Apr 9, 20245.418NONO
CVE-2023-5124MEDIUM
The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or foot
Jan 29, 20244.818NONO
CVE-2023-5087MEDIUM
The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or
Oct 16, 20235.418NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
86%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (27.3%)
Unknown0 (0.0%)
Required16 (72.7%)
Privileges Required
Low12 (54.5%)
High5 (22.7%)
None5 (22.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pagelayer.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pagelayer — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pagelayer's Products

View all 4 CNAs →

Top CWEs