📦 Brizy

by Brizy

🔍 What is Brizy?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-10960

CRITICAL CVSS 9.9 Feb 12, 2025

The Brizy Page Builder WordPress plugin allows authenticated users with Contributor-level access or higher to upload arbitrary files due to missing file type validation. This vulnerability can lead to...

CVE-2025-22763

HIGH CVSS 7.1 Jan 21, 2025

This vulnerability allows attackers to inject malicious scripts into Brizy Pro WordPress plugin pages through improper input sanitization. When exploited, it enables reflected cross-site scripting att...

CVE-2024-3242

HIGH CVSS 8.8 Jul 18, 2024

The Brizy Page Builder WordPress plugin allows authenticated attackers with contributor-level access or higher to upload arbitrary files due to insufficient file extension validation. This vulnerabili...

CVE-2024-1937

HIGH CVSS 7.1 Jul 16, 2024

The Brizy Page Builder WordPress plugin has an authorization bypass vulnerability that allows authenticated users with contributor-level access or higher to modify any published post content. This can...

CVE-2024-3667

HIGH CVSS 7.4 Jun 5, 2024

The Brizy Page Builder WordPress plugin has a stored XSS vulnerability in its 'Link To' field across multiple widgets. Authenticated attackers with contributor-level access or higher can inject malici...

CVE-2024-1940

HIGH CVSS 7.1 Jun 5, 2024

The Brizy Page Builder WordPress plugin has a stored XSS vulnerability that allows authenticated attackers with contributor-level access or higher to inject malicious scripts into pages. These scripts...

CVE-2024-1311

HIGH CVSS 8.8 Mar 13, 2024

The Brizy Page Builder WordPress plugin allows authenticated attackers with contributor-level access or higher to upload arbitrary files due to missing file type validation. This vulnerability can lea...

CVE-2020-36714

HIGH CVSS 7.4 Oct 20, 2023

The Brizy WordPress plugin up to version 1.0.125 contains an authorization bypass vulnerability due to an incorrect capability check in the is_administrator() function. This allows authenticated attac...

CVE-2025-4370

MEDIUM CVSS 5.3 Jul 29, 2025

The Brizy Page Builder WordPress plugin has an unauthenticated file upload vulnerability that allows attackers to upload .TXT files to the server. This affects all WordPress sites using Brizy Page Bui...

CVE-2025-32198

MEDIUM CVSS 6.5 Apr 10, 2025

This is a cross-site scripting (XSS) vulnerability in the Brizy WordPress plugin that allows attackers to inject malicious scripts into web pages. It affects all Brizy plugin versions up to 2.6.14, po...

CVE-2025-26901

MEDIUM CVSS 4.3 Apr 9, 2025

This CVE describes a missing authorization vulnerability in Brizy Pro WordPress plugin that allows attackers to bypass access controls. It affects all Brizy Pro installations up to version 2.6.1, pote...

CVE-2024-10322

MEDIUM CVSS 6.4 Feb 12, 2025

The Brizy Page Builder WordPress plugin has a stored XSS vulnerability that allows authenticated attackers with Author-level access or higher to upload malicious SVG files containing JavaScript. When ...

CVE-2024-6254

MEDIUM CVSS 4.3 Aug 8, 2024

The Brizy Page Builder WordPress plugin has a CSRF vulnerability that allows attackers to trick administrators into submitting malicious forms. This affects all versions up to 2.5.1. When unfiltered_h...

CVE-2024-1164

MEDIUM CVSS 6.4 Jun 5, 2024

The Brizy Page Builder WordPress plugin has a stored XSS vulnerability that allows authenticated attackers with contributor-level permissions or higher to inject malicious scripts into pages. These sc...

CVE-2024-3711

MEDIUM CVSS 4.3 May 23, 2024

The Brizy Page Builder WordPress plugin has a missing capability check vulnerability that allows authenticated users with contributor-level access or higher to modify plugin settings. Attackers can en...