cbcvebase.

Themeum Qubely vulnerabilities

9 known vulnerabilities affecting themeum/qubely.

Total CVEs
9
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM8

Vulnerabilities

Page 1 of 1
CVE-2021-24916P3HIGHCVSS 7.5PoCfixed in 1.8.62023-08-07
CVE-2021-24916 [HIGH] CWE-284 CVE-2021-24916: The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to ar The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.
nvd
CVE-2024-13228P3MEDIUMCVSS 6.5fixed in 1.8.142025-03-11
CVE-2024-13228 [MEDIUM] CWE-359 CVE-2024-13228: The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information E The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, password-protected, draft
nvd
CVE-2021-25013P4MEDIUMCVSS 6.5fixed in 1.7.82022-01-24
CVE-2021-25013 [MEDIUM] CWE-862 CVE-2021-25013: The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_de The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts
nvd
CVE-2023-0376P4MEDIUMCVSS 5.4fixed in 1.8.52024-01-16
CVE-2023-0376 [MEDIUM] CWE-79 CVE-2023-0376: The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options befo The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
nvd
CVE-2024-9601P4MEDIUMCVSS 5.4fixed in 1.8.132025-02-14
CVE-2024-9601 [MEDIUM] CWE-79 CVE-2024-9601: The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scrip The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject
nvd
CVE-2025-26767P4MEDIUMCVSS 5.4fixed in 1.8.13≤ 1.8.122025-02-16
CVE-2025-26767 [MEDIUM] CWE-79 CVE-2025-26767: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= 1.8.12.
nvd
CVE-2026-39638P4MEDIUMCVSS 5.9≤ 1.8.142026-04-08
CVE-2026-39638 [MEDIUM] CWE-79 CVE-2026-39638: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= 1.8.14.
nvd
CVE-2025-58663P4MEDIUMCVSS 4.3≤ 1.8.142025-09-22
CVE-2025-58663 [MEDIUM] CWE-862 CVE-2025-58663: Missing Authorization vulnerability in Themeum Qubely qubely allows Exploiting Incorrectly Configure Missing Authorization vulnerability in Themeum Qubely qubely allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Qubely: from n/a through <= 1.8.14.
nvd
CVE-2025-58249P4MEDIUMCVSS 4.3≤ 1.8.142025-09-22
CVE-2025-58249 [MEDIUM] CWE-201 CVE-2025-58249: Insertion of Sensitive Information Into Sent Data vulnerability in Themeum Qubely qubely allows Retr Insertion of Sensitive Information Into Sent Data vulnerability in Themeum Qubely qubely allows Retrieve Embedded Sensitive Data.This issue affects Qubely: from n/a through <= 1.8.14.
nvd
Themeum Qubely vulnerabilities | cvebase