Skip to content
Noroxi

colorlib records

10 published records for vendor colorlib.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
20%
Median publish → KEV
No record has entered KEV

All records

10 records
  • Epsilon Framework Themes (Various Versions) - Function Injection

    CriticalCVSS 9.8Proof of conceptEPSS 65%

    colorlib · activelloJun 6, 2023

  • Epsilon Framework Themes (Various Versions) - Unauthenticated Plugin Activation/Deactivation

    MediumCVSS 6.5No exploitEPSS 1%

    colorlib · activelloJun 6, 2023

  • CVE-2025-3662
    24Monitor

    FancyBox for WordPress < 3.3.6 - Unauthenticated Stored XSS

    MediumCVSS 6.1No exploitEPSS 0%

    colorlib · fancyboxJun 3, 2025

  • CVE-2024-1473
    21Monitor

    Coming Soon & Maintenance Mode by Colorlib <= 1.0.99 - Information Exposure

    MediumCVSS 5.3No exploitEPSS 1%

    colorlib · coming soon \& maintenance modeMar 20, 2024

  • WordPress Activello Theme <= 1.4.4 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    colorlib · activello themeApr 16, 2023

  • WordPress Activello Theme <= 1.4.4 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    colorlib · activelloApr 13, 2023

  • CVE-2015-1494
    19Monitor

    The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cro

    MediumCVSS 4.3Proof of conceptEPSS 6%

    colorlib · fancyboxFeb 17, 2015

  • CVE-2022-1945
    19Monitor

    Coming Soon and Maintenance by Colorlib < 1.0.99 - Admin+ Stored Cross Site Scripting

    MediumCVSS 4.8No exploitEPSS 1%

    colorlib · coming soon \& maintenance modeJun 20, 2022

  • CVE-2024-0662
    19Monitor

    The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions 3.0.2 to 3.3.3 d

    MediumCVSS 4.8No exploitEPSS 0%

    colorlib · fancyboxApr 9, 2024

  • WordPress Simple Custom Post Order plugin <= 2.5.7 - Broken Access Control vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    colorlib · simple custom post orderOct 21, 2024