Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pixelgrade

First CVE: Jan 30, 2023Active for: 3 yearsTotal CVEs: 13
17.9
VTI Score
Low

Pixelgrade develops a suite of WordPress plugins and themes focused on site customization and content-handling functionality, positioning them across a modestly represented but more-prominent-than-typical share of the WordPress ecosystem. The vendor's vulnerability exposure recurs through web-application input-handling weaknesses, chiefly cross-site request forgery and cross-site scripting flaws that reflect the challenges of managing user input and state in plugin contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pixelgrade over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2023
3 years ago
Most Recent CVE
Jan 23, 2026
182 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-24528MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks nova-blocks allows DOM-Based XSS.This issue affects Nov
Jan 23, 20266.525NONO
CVE-2023-27633HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Customify – Intuitive Website Styling plugin <= 2.10.4 versions.
Nov 22, 20238.825NONO
CVE-2023-25487HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade PixTypes plugin <= 1.4.14 versions.
Jul 11, 20238.825NONO
CVE-2023-23704HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.6 versions.
Jul 11, 20238.825NONO
CVE-2023-45655HIGH
Cross-Site Request Forgery (CSRF) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions.
Oct 16, 20238.823NONO
CVE-2023-45654HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions.
Oct 16, 20238.823NONO
CVE-2022-4671MEDIUM
The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a rol
Jan 30, 20235.421NONO
CVE-2022-46844MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions.
May 9, 20235.420NONO
CVE-2025-31819MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks nova-blocks.This issue affects Nova Blocks: from n/a th
Apr 1, 20256.519NONO
CVE-2024-8241MEDIUM
The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all versions up t
Sep 10, 20245.418NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
62%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required13 (100.0%)
Privileges Required
Low6 (46.2%)
High1 (7.7%)
None6 (46.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pixelgrade.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pixelgrade — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pixelgrade's Products

View all 3 CNAs →

Top CWEs