Products: 4
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-56275

    WordPress Envato Elements plugin <= 2.0.14 - Server Side Request Forgery (SSRF) vulnerability

    Last Modified: Apr 28, 2026
    Published: Jan 07, 2025

    CVE-2024-37550

    WordPress Template Kit – Export plugin <= 1.0.22 - Cross Site Scripting (XSS) vulnerability

    Last Modified: Nov 21, 2024
    Published: Jul 21, 2024

    CVE-2024-2334

    Template Kit – Import <= 1.0.14 - Authenticated(Author+) Stored Cross-Site Scripting via template upload

    Last Modified: Apr 15, 2026
    Published: Apr 09, 2024

    CVE-2021-4330

    Envato Elements <= 2.0.10 & Template Kit <= 1.0.13 - Authenticated (Contributor+) Arbitrary File Upload

    Last Modified: Apr 08, 2026
    Published: Mar 07, 2023

    CVE-2013-5962

    Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.

    Last Modified: Apr 11, 2025
    Published: Sep 30, 2013
    Items Per Page
    Envato Vulnerabilities & Security CVEs | CVE-DB