Plugin Vulnerability Hub
Plugin 18 known issues Latest disclosed Dec 18, 2025

Colibri Page Builder Vulnerabilities

Review known vulnerability records for the WordPress plugin Colibri Page Builder (`colibri-page-builder`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-11747, CVE-2025-11376 and CVE-2025-9560, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
18
High or Critical
1
Patch Coverage
100%
Last Updated
Dec 19, 2025
Priority CVE Quick Links

Fast paths into Colibri Page Builder CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
18
CVE-2023-2188 High 1.0.229
CVE-2023-2188 Colibri Page Builder SQL Injection

Colibri Page Builder <= 1.0.227 - Authenticated (Administrator+) SQL Injection via post_id

CVE-2025-11747 Medium 1.0.358
CVE-2025-11747 Colibri Page Builder Stored Cross-Site Scripting

Colibri Page Builder <= 1.0.345 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

CVE-2025-11376 Medium 1.0.342
CVE-2025-11376 Colibri Page Builder Stored Cross-Site Scripting

Colibri Page Builder <= 1.0.335 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2025-9560 Medium 1.0.335
CVE-2025-9560 Colibri Page Builder Stored Cross-Site Scripting

Colibri Page Builder <= 1.0.334 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_newsletter Shortcode

CVE-2025-32185 Medium 1.0.332
CVE-2025-32185 Colibri Page Builder Stored Cross-Site Scripting

Colibri Page Builder <= 1.0.319 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-4451 Medium 1.0.277
CVE-2024-4451 Colibri Page Builder Stored Cross-Site Scripting

Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player Shortcode

CVE-2024-5038 Medium 1.0.277
CVE-2024-5038 Colibri Page Builder Stored Cross-Site Scripting

Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

CVE-2024-3337 Medium 1.0.274
CVE-2024-3337 Colibri Page Builder Stored Cross-Site Scripting

Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri_breadcrumb_element' Shortcode

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Colibri Page Builder so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
18 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 1 high severity finding.
Recent CVEs
CVE-2025-11747, CVE-2025-11376 and CVE-2025-9560
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Colibri Page Builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-11747
CVE-2025-11747: Colibri Page Builder <= 1.0.345 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss...

Published
Dec 18, 2025
Patched Release
1.0.358
Affected Versions
Versions up to 1.0.345
Next Step
Update to 1.0.358 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11376
CVE-2025-11376: Colibri Page Builder <= 1.0.335 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...

Published
Dec 12, 2025
Patched Release
1.0.342
Affected Versions
Versions up to 1.0.335
Next Step
Update to 1.0.342 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-9560
CVE-2025-9560: Colibri Page Builder <= 1.0.334 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_newsletter Shortcode

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input sanitization and output escaping on user supplied attributes. This make...

Published
Oct 10, 2025
Patched Release
1.0.335
Affected Versions
Versions up to 1.0.334
Next Step
Update to 1.0.335 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-59593
CVE-2025-59593: Colibri Page Builder < 1.0.334 - Authenticated (Shop manager+) Stored Cross-Site Scripting

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.0.334 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject...

Published
Sep 22, 2025
Patched Release
1.0.334
Affected Versions
Versions before 1.0.334
Next Step
Update to 1.0.334 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-32185
CVE-2025-32185: Colibri Page Builder <= 1.0.319 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.319 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and a...

Published
Apr 04, 2025
Patched Release
1.0.332
Affected Versions
Versions up to 1.0.319
Next Step
Update to 1.0.332 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4451
CVE-2024-4451: Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player Shortcode

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This ma...

Published
Jun 06, 2024
Patched Release
1.0.277
Affected Versions
Versions up to 1.0.276
Next Step
Update to 1.0.277 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-5038
CVE-2024-5038: Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fo...

Published
Jun 05, 2024
Patched Release
1.0.277
Affected Versions
Versions up to 1.0.276
Next Step
Update to 1.0.277 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3340
CVE-2024-3340: Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri-gallery-slideshow' Shortcode

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gallery-slideshow' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes....

Published
Apr 22, 2024
Patched Release
1.0.274
Affected Versions
Versions up to 1.0.272
Next Step
Update to 1.0.274 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3337
CVE-2024-3337: Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri_breadcrumb_element' Shortcode

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_breadcrumb_element' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes....

Published
Apr 22, 2024
Patched Release
1.0.274
Affected Versions
Versions up to 1.0.272
Next Step
Update to 1.0.274 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3338
CVE-2024-3338: Colibri Page Builder <= 1.0.262 - Authenticated (Author+) Stored Cross-Site Scripting

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter in all versions up to, and including, 1.0.262 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Published
Apr 22, 2024
Patched Release
1.0.264
Affected Versions
Versions up to 1.0.262
Next Step
Update to 1.0.264 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2839
CVE-2024-2839: Colibri Page Builder <= 1.0.263 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_post_title' shortcode in all versions up to, and including, 1.0.263 due to insufficient input sanitization and output escaping on user supplied attributes such as...

Published
Apr 01, 2024
Patched Release
1.0.270
Affected Versions
Versions up to 1.0.263
Next Step
Update to 1.0.270 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-28004
CVE-2024-28004: Colibri Page Builder <= 1.0.248 - Missing Authorization

The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_colibri_page_builder_wpmu_setting AJAX action in all versions up to, and including, 1.0.248. This makes it possible for authenticated...

Published
Mar 26, 2024
Patched Release
1.0.249
Affected Versions
Versions up to 1.0.248
Next Step
Update to 1.0.249 or newer if supported.