BoldGrid records
27 published records for vendor boldgrid.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 7.4%
- Pre-auth RCE
- 0
- With a fix record
- 14.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-862 Missing Authorization3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2013-2010Weaponized | WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerabilityautomattic · wp super cache · CWE-74 | Critical9.8 | — | 73.9% | Feb 12, 2020 |
36Monitor | CVE-2019-6715Proof of concept | pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL fieboldgrid · w3 total cache | High7.5 | — | 19.4% | Apr 1, 2019 |
35Monitor | CVE-2024-12365Proof of concept | W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgeryboldgrid · w3 total cache · CWE-862 | High8.5 | — | 1.8% | Jan 14, 2025 |
35Monitor | CVE-2023-25480No exploit | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.24.1 is vulnerable to Cross Site Request Forgery (CSRF)boldgrid · post and page builder · CWE-352 | High8.8 | — | 0.3% | Oct 6, 2023 |
32Monitor | CVE-2012-6077Proof of concept | W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.boldgrid · w3 total cache · CWE-200 | High7.5 | — | 5.4% | Nov 22, 2019 |
31Monitor | CVE-2012-6078No exploit | W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.boldgrid · w3 total cache · CWE-200 | High7.5 | — | 2.3% | Nov 22, 2019 |
31Monitor | CVE-2024-12008Proof of concept | W3 Total Cache <= 2.8.1 Information Exposure via Log Filesboldgrid · w3 total cache · CWE-200 | High7.5 | — | 2.3% | Jan 14, 2025 |
31Monitor | CVE-2012-6079No exploit | W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via tboldgrid · w3 total cache · CWE-200 | High7.5 | — | 2.1% | Nov 22, 2019 |
30Monitor | CVE-2020-36848Weaponized | Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Downloadboldgrid · total upkeep · CWE-200 | High7.5 | — | 1.6% | Jul 12, 2025 |
30Monitor | CVE-2023-5359Proof of concept | W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintextboldgrid · w3 total cache · CWE-200 | High7.5 | — | 0.8% | Sep 24, 2024 |
30Monitor | CVE-2024-24869No exploit | WordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerabilityboldgrid · total upkeep · CWE-22 | High7.5 | — | 0.7% | May 17, 2024 |
28Monitor | CVE-2024-9461No exploit | Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup Settingsboldgrid · total upkeep · CWE-78 | High7.2 | — | 1.0% | Nov 26, 2024 |
28Monitor | CVE-2025-2257No exploit | Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injectionboldgrid · total upkeep · CWE-78 | High7.2 | — | 0.9% | Mar 26, 2025 |
27Monitor | CVE-2014-9414No exploit | The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct crossboldgrid · w3 total cache · CWE-352 | Medium6.8 | — | 1.4% | Dec 24, 2014 |
26Monitor | CVE-2025-0859No exploit | Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Functionboldgrid · post and page builder · CWE-22 | Medium6.5 | — | 0.7% | Feb 6, 2025 |
26Monitor | CVE-2024-13907No exploit | Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgeryboldgrid · total upkeep · CWE-918 | Medium6.5 | — | 0.5% | Feb 27, 2025 |
25Monitor | CVE-2021-24452Proof of concept | W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context)boldgrid · w3 total cache · CWE-79 | Medium6.1 | — | 1.9% | Jul 19, 2021 |
25Monitor | CVE-2021-24436Proof of concept | W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context)boldgrid · w3 total cache · CWE-79 | Medium6.1 | — | 1.9% | Jul 19, 2021 |
21Monitor | CVE-2024-12006No exploit | W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivationboldgrid · w3 total cache · CWE-862 | Medium5.3 | — | 0.5% | Jan 14, 2025 |
21Monitor | CVE-2024-2950No exploit | BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.14 - Information Exposureboldgrid · easy seo · CWE-200 | Medium5.3 | — | 0.5% | Apr 6, 2024 |
21Monitor | CVE-2024-6848No exploit | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Uploadboldgrid · post and page builder · CWE-79 | Medium5.4 | — | 0.5% | Jul 20, 2024 |
21Monitor | CVE-2024-2888No exploit | WordPress Post and Page Builder by BoldGrid plugin <= 1.26.2 - Cross Site Scripting (XSS) vulnerabilityboldgrid · post and page builder · CWE-79 | Medium5.4 | — | 0.3% | Mar 26, 2024 |
21Monitor | CVE-2025-22759No exploit | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerabilityboldgrid · post and page builder by boldgrid - visual drag and drop editor · CWE-79 | Medium5.4 | — | 0.3% | Jan 15, 2025 |
21Monitor | CVE-2024-4400No exploit | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.4 - Authenticated (Contributer+) Stored Cross-Site Scriptingboldgrid · post and page builder · CWE-79 | Medium5.4 | — | 0.3% | May 16, 2024 |
19Monitor | CVE-2021-24427No exploit | W3 Total Cache < 2.1.3 - Authenticated Stored XSSboldgrid · w3 total cache · CWE-79 | Medium4.8 | — | 0.6% | Jul 12, 2021 |
- CVE-2013-201061This week
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
CriticalCVSS 9.8WeaponizedEPSS 74%automattic · wp super cacheFeb 12, 2020
- CVE-2019-671536Monitor
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL fie
HighCVSS 7.5Proof of conceptEPSS 19%boldgrid · w3 total cacheApr 1, 2019
- CVE-2024-1236535Monitor
W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery
HighCVSS 8.5Proof of conceptEPSS 2%boldgrid · w3 total cacheJan 14, 2025
- CVE-2023-2548035Monitor
WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.24.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%boldgrid · post and page builderOct 6, 2023
- CVE-2012-607732Monitor
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
HighCVSS 7.5Proof of conceptEPSS 5%boldgrid · w3 total cacheNov 22, 2019
- CVE-2012-607831Monitor
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
HighCVSS 7.5No exploitEPSS 2%boldgrid · w3 total cacheNov 22, 2019
- CVE-2024-1200831Monitor
W3 Total Cache <= 2.8.1 Information Exposure via Log Files
HighCVSS 7.5Proof of conceptEPSS 2%boldgrid · w3 total cacheJan 14, 2025
- CVE-2012-607931Monitor
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via t
HighCVSS 7.5No exploitEPSS 2%boldgrid · w3 total cacheNov 22, 2019
- CVE-2020-3684830Monitor
Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
HighCVSS 7.5WeaponizedEPSS 2%boldgrid · total upkeepJul 12, 2025
- CVE-2023-535930Monitor
W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext
HighCVSS 7.5Proof of conceptEPSS 1%boldgrid · w3 total cacheSep 24, 2024
- CVE-2024-2486930Monitor
WordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerability
HighCVSS 7.5No exploitEPSS 1%boldgrid · total upkeepMay 17, 2024
- CVE-2024-946128Monitor
Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup Settings
HighCVSS 7.2No exploitEPSS 1%boldgrid · total upkeepNov 26, 2024
- CVE-2025-225728Monitor
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection
HighCVSS 7.2No exploitEPSS 1%boldgrid · total upkeepMar 26, 2025
- CVE-2014-941427Monitor
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross
MediumCVSS 6.8No exploitEPSS 1%boldgrid · w3 total cacheDec 24, 2014
- CVE-2025-085926Monitor
Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function
MediumCVSS 6.5No exploitEPSS 1%boldgrid · post and page builderFeb 6, 2025
- CVE-2024-1390726Monitor
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgery
MediumCVSS 6.5No exploitEPSS 0%boldgrid · total upkeepFeb 27, 2025
- CVE-2021-2445225Monitor
W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context)
MediumCVSS 6.1Proof of conceptEPSS 2%boldgrid · w3 total cacheJul 19, 2021
- CVE-2021-2443625Monitor
W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context)
MediumCVSS 6.1Proof of conceptEPSS 2%boldgrid · w3 total cacheJul 19, 2021
- CVE-2024-1200621Monitor
W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation
MediumCVSS 5.3No exploitEPSS 1%boldgrid · w3 total cacheJan 14, 2025
- CVE-2024-295021Monitor
BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.14 - Information Exposure
MediumCVSS 5.3No exploitEPSS 1%boldgrid · easy seoApr 6, 2024
- CVE-2024-684821Monitor
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Upload
MediumCVSS 5.4No exploitEPSS 0%boldgrid · post and page builderJul 20, 2024
- CVE-2024-288821Monitor
WordPress Post and Page Builder by BoldGrid plugin <= 1.26.2 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%boldgrid · post and page builderMar 26, 2024
- CVE-2025-2275921Monitor
WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%boldgrid · post and page builder by boldgrid - visual drag and drop editorJan 15, 2025
- CVE-2024-440021Monitor
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.4 - Authenticated (Contributer+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%boldgrid · post and page builderMay 16, 2024
- CVE-2021-2442719Monitor
W3 Total Cache < 2.1.3 - Authenticated Stored XSS
MediumCVSS 4.8No exploitEPSS 1%boldgrid · w3 total cacheJul 12, 2021