← WordPress Vulnerabilities
WordPress security by component

Colibri Page Builder

Colibri Page Builder is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Dec 19, 2025; the highest CVE/CNA score is 7.2.

Plugin slug: colibri-page-builder

CVE-2025-11747: Colibri Page Builder: Cross-site scripting

Colibri Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedDec 19, 2025
Safe version guidanceSee mitigation notes
Safe version
Dec 19, 2025 CVE-2025-11747
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Dec 13, 2025 CVE-2025-11376
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Oct 22, 2025 CVE-2025-59593
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Oct 11, 2025 CVE-2025-9560
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Apr 04, 2025 CVE-2025-32185
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 07, 2024 CVE-2024-4451
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 06, 2024 CVE-2024-5038
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-3340
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
May 02, 2024 CVE-2024-3338
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD5.4
May 02, 2024 CVE-2024-3337
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 02, 2024 CVE-2024-2839
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 28, 2024 CVE-2024-28004
Colibri Page Builder: A security weakness
Colibri Page Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Mar 09, 2024 CVE-2024-1870
Colibri Page Builder: A security weakness
Colibri Page Builder is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 23, 2024 CVE-2024-1362
Colibri Page Builder: Cross-site request forgery
Colibri Page Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Feb 23, 2024 CVE-2024-1361
Colibri Page Builder: Cross-site request forgery
Colibri Page Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Jan 11, 2024 CVE-2023-6988
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 21, 2023 CVE-2023-50833
Colibri Page Builder: Cross-site scripting
Colibri Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Aug 31, 2023 CVE-2023-2188
Colibri Page Builder: SQL injection
Colibri Page Builder is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD4.9