Wix maintains a web-building and hosting platform where its vulnerability footprint centers on template-engine and code-generation mechanisms, reflecting the dynamic nature of customer-authored site content and embedded components such as the JAM framework and MySQL integration. The recurring exposure involves code injection and improper neutralization of template directives, typical of platforms that must safely execute or interpolate user-supplied expressions while isolating them from the hosting environment. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wix over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3841CRITICAL A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.py | Apr 21, 2025 | 9.8 | 28 | NO | NO |
CVE-2023-39021CRITICAL wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploite | Jul 28, 2023 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wix.
Media articles that mention a CVE ID that affects a product developed by Wix — matched by CVE ID, not by vendor name.