CVE Tools

Colorlib

1 CVEs tracked since 2015. Since Feb 2015, none of them reached CISA KEV.

Colorlib CVEs per month

Feb 2015 to Feb 2015. Point at a month, or focus the strip and use the arrow keys.
Colorlib CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-0210

Products

The products that kept showing up in Colorlib's monthly top three, with their CVEs summed over those months.

  1. Fancybox11 month

Latest CVEs

The 10 most recently published vulnerabilities affecting Colorlib.

  1. CVE-2025-3662FancyBox for WordPress < 3.3.6 - Unauthenticated Stored XSS6.1
  2. CVE-2024-49321WordPress Simple Custom Post Order plugin <= 2.5.7 - Broken Access Control vulnerability4.3
  3. CVE-2024-0662The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions 3.0.2 to 3.3.3 due to insufficient input sanitization and output escaping...4.4
  4. CVE-2024-1473Coming Soon & Maintenance Mode by Colorlib <= 1.0.99 - Information Exposure5.3
  5. CVE-2020-36721Epsilon Framework Themes (Various Versions) - Unauthenticated Plugin Activation/Deactivation6.5
  6. CVE-2020-36708Epsilon Framework Themes (Various Versions) - Function Injection9.8
  7. CVE-2022-45849WordPress Activello Theme <= 1.4.4 is vulnerable to Cross Site Scripting (XSS)5.4
  8. CVE-2022-45358WordPress Activello Theme <= 1.4.4 is vulnerable to Cross Site Scripting (XSS)5.4
  9. CVE-2022-1945Coming Soon and Maintenance by Colorlib < 1.0.99 - Admin+ Stored Cross Site Scripting4.8
  10. CVE-2015-1494The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter...4.3

The record

Peak rank
#94 in Feb 2015
Busiest month shown
Feb 2015, 1 CVEs
Months with a KEV entry
0 since Feb 2015
Monthly snapshots
1 since 2015
Colorlib's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store