CVE Tools

Extendthemes

4 CVEs tracked since 2024. Since Jun 2024, none of them reached CISA KEV.

Extendthemes CVEs per month

Jun 2024 to Jun 2024. Point at a month, or focus the strip and use the arrow keys.
Extendthemes CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0640

Products

The products that kept showing up in Extendthemes's monthly top three, with their CVEs summed over those months.

  1. Colibri Page Builder21 month
  2. Materialis11 month
  3. Materialis Companion11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Extendthemes.

  1. CVE-2026-14472Kubio AI Page Builder <= 2.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via kubio/copyright Block Content6.4
  2. CVE-2026-16779Kubio AI Page Builder <= 2.8.5 - Missing Authorization to Authenticated (Contributor+) Front-Page/Menu/Template Configuration Reversion via kubio_restore_front_page AJAX Action4.3
  3. CVE-2026-5427Kubio AI Page Builder <= 2.7.2 - Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes5.3
  4. CVE-2025-62751WordPress Vireo theme <= 1.0.24 - Broken Access Control vulnerability4.3
  5. CVE-2025-11747Colibri Page Builder <= 1.0.345 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode6.4
  6. CVE-2025-11376Colibri Page Builder <= 1.0.335 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
  7. CVE-2025-59593WordPress Colibri Page Builder Plugin < 1.0.334 - Cross Site Scripting (XSS) Vulnerability5.9
  8. CVE-2025-9560Colibri Page Builder <= 1.0.334 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_newsletter Shortcode6.4
  9. CVE-2025-8487Kubio AI Page Builder <= 2.6.3 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation5.4
  10. CVE-2025-32185WordPress Colibri Page Builder plugin <= 1.0.329 - Cross Site Scripting (XSS) vulnerability6.5
  11. CVE-2025-2294Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion9.8
  12. CVE-2024-13516Kubio AI Page Builder <= 2.3.5 - Reflected Cross-Site Scripting6.1
  13. CVE-2024-37458WordPress Highlight theme <= 1.0.29 - Cross Site Request Forgery (CSRF) vulnerability4.3
  14. CVE-2024-37431WordPress Mesmerize theme <= 1.6.120 - Cross Site Request Forgery (CSRF) vulnerability4.3
  15. CVE-2024-5020Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library6.4

The record

Peak rank
#177 in Jun 2024
Busiest month shown
Jun 2024, 4 CVEs
Months with a KEV entry
0 since Jun 2024
Monthly snapshots
1 since 2024
Extendthemes's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store