CVE Tools

Beaverbuilder

6 CVEs tracked since 2024. Since Mar 2024, none of them reached CISA KEV.

Beaverbuilder CVEs per month

Mar 2024 to Mar 2024. Point at a month, or focus the strip and use the arrow keys.
Beaverbuilder CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0360

Products

The products that kept showing up in Beaverbuilder's monthly top three, with their CVEs summed over those months.

  1. Beaver Builder Page Builder – Drag and Drop Website Builder61 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Beaverbuilder.

  1. CVE-2026-18021Beaver Builder Page Builder <= 2.10.3.1 - Unauthenticated Arbitrary Shortcode Execution6.5
  2. CVE-2026-17090Beaver Builder Page Builder <= 2.10.2.2 - Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter6.4
  3. CVE-2026-2481Beaver Builder Page Builder – Drag and Drop Website Builder <= 2.10.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'settings[js]'6.4
  4. CVE-2026-1231Beaver Builder Page Builder – Drag and Drop Website Builder <= 2.10.0.5 - Authenticated (Custom+) Missing Authorization to Stored Cross-Site Scripting via Global Settings6.4
  5. CVE-2025-12934Beaver Builder – WordPress Page Builder <= 2.9.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update8.1
  6. CVE-2025-12558Beaver Builder – WordPress Page Builder <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure4.3
  7. CVE-2025-12782Beaver Builder – WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Builder Status Tampering4.3
  8. CVE-2025-11726Beaver Builder – WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Global Preset Modification4.3
  9. CVE-2025-8897Beaver Builder Plugin (Lite Version) <= 2.9.2.1 - Reflected Cross-Site Scripting6.1
  10. CVE-2024-11832Beaver Builder – WordPress Page Builder <= 2.8.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
  11. CVE-2024-9505Beaver Builder – WordPress Page Builder <= 2.8.4.2 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Widget6.4
  12. CVE-2024-9049Beaver Builder – WordPress Page Builder <= 2.8.3.6 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Group Module6.4
  13. CVE-2024-7620Customizer Export/Import <= 0.9.7 - Authenticated (Admin+) Arbitrary File Upload via Customization Settings Import6.6
  14. CVE-2024-7895Beaver Builder (Lite Version) <= 2.8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter6.4
  15. CVE-2024-4430Beaver Builder <= 2.8.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via photo widget crop attribute6.4

The record

Peak rank
#126 in Mar 2024
Busiest month shown
Mar 2024, 6 CVEs
Months with a KEV entry
0 since Mar 2024
Monthly snapshots
1 since 2024
Beaverbuilder's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store