SecAlerts
p

pagelayer

Security Risk Profile

31
/100
low

Security Risk Score

Comprehensive risk assessment based on 27 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 1, 2021 to present

27
Total CVEs
3
Critical+High
0
Exploited
1
Unpatched

Threat Assessment

Avg CVSS
5.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
31/100
low

Severity Distribution

Critical
0
High
3
Medium
24
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
XSS
19
2
CSRF
3
3
CRLF Injection
1
4
Input Validation
1

Most Affected Products

1. PageLayer Pagelayer WordPress17
2. Pagelayer Pagelayer9
3. Pagelayer Page Builder: Pagelayer5
4. Pagelayer Pagelayer WordPress2
5. Pagelayer Drag and Drop website builder1

Recent Vulnerabilities

See more →
CVE-2026-2470
CVSS 4.3medium

Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'

6/13/2026🔧 No Patch
CVE-2026-3297
CVSS 6.4medium

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block

6/13/2026🔧 No Patch
CVE-2026-2509
CVSS 6.4medium

Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes

4/8/2026🔧 No Patch
CVE-2026-2442
CVSS 5.3medium

Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'

3/28/2026🔧 No Patch
CVE-2025-12366
CVSS 4.3medium

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference

11/13/2025🔧 No Patch
CVE-2025-4223
CVSS 4.7medium

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter

5/24/2025🔧 No Patch
CVE-2024-13427
CVSS 6.4medium

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link

5/24/2025🔧 No Patch
CVE-2024-8618
CVSS 4.8medium

Page Builder: Pagelayer < 1.9.0- Admin+ Stored XSS

5/15/2025🔧 No Patch
CVE-2024-8426
CVSS 4.8medium

Pagelayer < 1.8.8 - Admin+ Stored XSS

5/15/2025🔧 No Patch
CVE-2025-2104
CVSS 4.3medium

Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication

3/13/2025🔧 No Patch

Monitor pagelayer in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.