Qubely
Vendor:
First CVE: Jan 24, 2022 · Active for 4 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Qubely over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2022
4 years ago
Most Recent CVE
Jul 23, 2026
3 days ago
CVE Severity & Scoring
Qubely10 CVEs
90%
10%
All CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None6 (60.0%)
Unknown0 (0.0%)
Required4 (40.0%)
Privileges Required
Low7 (70.0%)
High1 (10.0%)
None2 (20.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24916HIGH The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action. | Aug 7, 2023 | 7.5 | 32 | NO | YES |
CVE-2026-65531MEDIUM Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. | Jul 23, 2026 | 4.8 | 23 | NO | NO |
CVE-2021-25013MEDIUM The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted b | Jan 24, 2022 | 6.5 | 23 | NO | NO |
CVE-2026-39638MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a th | Apr 8, 2026 | 5.9 | 22 | NO | NO |
CVE-2024-13228MEDIUM The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content | Mar 11, 2025 | 6.5 | 18 | NO | NO |
CVE-2025-26767MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a th | Feb 16, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-58663MEDIUM Missing Authorization vulnerability in Themeum Qubely qubely allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Qubely: from n/a through <= | Sep 22, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-58249MEDIUM Insertion of Sensitive Information Into Sent Data vulnerability in Themeum Qubely qubely allows Retrieve Embedded Sensitive Data.This issue affects Qubely: from n/a through <= 1.8. | Sep 22, 2025 | 4.3 | 17 | NO | NO |
CVE-2024-9601MEDIUM The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in all versions up to, and includ | Feb 14, 2025 | 5.4 | 17 | NO | NO |
CVE-2023-0376MEDIUM The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could all | Jan 16, 2024 | 5.4 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Qubely
Top CWEs
Versions
No cataloged versions.