Colorlib

    Dashboard / Vendors

    Products: 12
    Vulnerabilities: 10
    Known Exploited: 0
    1
    Critical Level Threats
    0
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-3662

    FancyBox for WordPress < 3.3.6 - Unauthenticated Stored XSS

    Last Modified: Jun 05, 2025
    Published: Jun 03, 2025

    CVE-2024-49321

    WordPress Simple Custom Post Order plugin <= 2.5.7 - Broken Access Control vulnerability

    Last Modified: Apr 01, 2026
    Published: Oct 21, 2024

    CVE-2024-0662

    The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions 3.0.2 to 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Last Modified: May 06, 2025
    Published: Apr 09, 2024

    CVE-2024-1473

    Coming Soon & Maintenance Mode by Colorlib <= 1.0.99 - Information Exposure

    Last Modified: Apr 08, 2026
    Published: Mar 20, 2024

    CVE-2020-36721

    Epsilon Framework Themes (Various Versions) - Unauthenticated Plugin Activation/Deactivation

    Last Modified: Apr 08, 2026
    Published: Jun 07, 2023
    Items Per Page
    Colorlib Vulnerabilities & Security CVEs | CVE-DB