SecAlerts
b

blocksy

Security Risk Profile

67
/100
high

Security Risk Score

Comprehensive risk assessment based on 14 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 9, 2024 to present

14
Total CVEs
4
Critical+High
1
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
7.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
67/100
high
⚠️ 1 Active Exploits🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
3
High
1
Medium
10
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
10
2
Malicious File Upload
3
3
Input Validation
1

Most Affected Products

1. creativethemes Blocksy Wordpress5
2. Blocksy Companion4
3. Blocksy Blocksy Companion3
4. Blocksy Blocksy3
5. creativethemes Blocksy Companion Wordpress2

Recent Vulnerabilities

See more →
CVE-2026-107645
CVSS 9.1critical

Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter

Oct 10, 2026🔧 No Patch
CVE-2026-18488
CVSS 6.4medium

Blocksy Companion <= 2.1.51 - Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data)

Sep 1, 2026🔧 No Patch
CVE-2026-15158
CVSS 9.8critical

Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter

Jul 9, 2026🔧 No Patch
CVE-2026-58480
CVSS 9.2critical

Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments

Jul 8, 2026⚠ Exploited🔧 No Patch
CVE-2025-12846
CVSS 8.8high

Blocksy Companion <= 2.1.19 - Authenticated (Author+) Arbitrary File Upload via SVG Upload Bypass

Nov 11, 2025🔧 No Patch
CVE-2025-12475
CVSS 6.4medium

Blocksy Companion <= 2.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 30, 2025🔧 No Patch
CVE-2025-9565
CVSS 6.4EPSS 0%medium

Blocksy Companion <= 2.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via blocksy_newsletter_subscribe Shortcode

Sep 17, 2025🔧 No Patch
CVE-2024-11420
CVSS 6.4medium

Blocksy <= 2.0.77 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 5, 2024
CVE-2024-4943
CVSS 6.4EPSS 0%medium

Blocksy <= 2.0.46 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 21, 2024🔧 No Patch
CVE-2024-4487
CVSS 6.4EPSS 0%medium

Blocksy Companion <= 2.0.45 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Uploads

May 11, 2024🔧 No Patch

Monitor blocksy in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.