vciy

CVEs we hold for Boldgrid

Records whose assigning authority named Boldgrid as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9282W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameterboldgrid W3 Total Cache
CVE-2026-78438W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutatorboldgrid W3 Total Cache
CVE-2026-66708WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerabilityBoldGrid Total Upkeep
CVE-2026-66695WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerabilityBoldGrid W3 Total Cache
CVE-2026-57623WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerabilityBoldGrid W3 Total Cache
CVE-2026-57428WordPress Sprout Clients plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnerabilityBoldGrid Sprout Clients
CVE-2026-57418WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Access Control vulnerabilityBoldGrid Client Invoicing by Sprout Invoices
CVE-2026-5032W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Headerboldgrid W3 Total Cache
CVE-2026-39595WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerabilityBoldGrid W3 Total Cache
CVE-2026-39562WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.10 - Broken Access Control vulnerabilityBoldGrid Client Invoicing by Sprout Invoices
CVE-2026-32484WordPress weForms plugin <= 1.6.26 - PHP Object Injection vulnerabilityBoldGrid weForms
CVE-2026-32424WordPress Sprout Clients plugin <= 3.2.2 - Cross Site Scripting (XSS) vulnerabilityBoldGrid Sprout Clients
CVE-2026-32401WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.9 - Local File Inclusion vulnerabilityBoldGrid Client Invoicing by Sprout Invoices
CVE-2026-3143Total Upkeep <= 1.17.1 - Missing Authorization to Unauthenticated Rollback CancellationBoldGrid
CVE-2026-27384WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerabilityBoldGrid W3 Total Cache
CVE-2026-2707weForms <= 1.6.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST APIboldgrid weForms – Easy Drag & Drop Contact Form Builder…
CVE-2026-25364WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.8 - Broken Access Control vulnerabilityBoldGrid Client Invoicing by Sprout Invoices
CVE-2026-18109W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Nameboldgrid W3 Total Cache
CVE-2025-69345WordPress Post and Page Builder by BoldGrid plugin <= 1.27.9 - Broken Access Control vulnerabilityBoldGrid
CVE-2025-69028WordPress weForms plugin <= 1.6.25 - Broken Access Control vulnerabilityBoldGrid weForms
CVE-2025-66118WordPress Sprout Clients plugin <= 3.2.1 - Cross Site Scripting (XSS) vulnerabilityBoldGrid Sprout Clients
CVE-2025-64229WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.7 - Broken Access Control vulnerabilityBoldGrid Client Invoicing by Sprout Invoices
CVE-2025-64227WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.7 - PHP Object Injection vulnerabilityBoldGrid Client Invoicing by Sprout Invoices
CVE-2025-52713WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.8 - Server Side Request…BoldGrid
CVE-2025-52712WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 - Path Traversal VulnerabilityBoldGrid
CVE-2025-52711WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.8 - Cross Site Request Forgery…BoldGrid
CVE-2025-31797WordPress Sprout Clients plugin <= 3.2 - Cross Site Scripting (XSS) vulnerabilityBoldGrid Sprout Clients
CVE-2025-24606WordPress Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin <=20.8.1 - Broken…BoldGrid Client Invoicing by Sprout Invoices
CVE-2025-22759WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.5 - Cross Site Scripting (XSS)…BoldGrid
CVE-2025-2257Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command…BoldGrid
CVE-2025-22512WordPress Help Scout Plugin <= 6.5.6 - Broken Access Control vulnerabilityBoldGrid Help Scout
CVE-2025-0859Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via…BoldGrid – Visual Drag and Drop Editor
CVE-2024-9461Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup SettingsBoldGrid
CVE-2024-6848Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored…BoldGrid – Visual Drag and Drop Editor
CVE-2024-53819WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.0 - Insecure Direct Object References (IDOR) vulnerabilityBoldGrid Client Invoicing by Sprout Invoices
CVE-2024-4400Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.4 - Authenticated (Contributer+) Stored…BoldGrid – Visual Drag and Drop Editor
CVE-2024-2950BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.14 - Information ExposureBoldGrid Easy SEO – Simple and Effective SEO
CVE-2024-2888WordPress Post and Page Builder by BoldGrid plugin <= 1.26.2 - Cross Site Scripting (XSS) vulnerabilityBoldGrid – Visual Drag and Drop Editor
CVE-2024-24869WordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerabilityBoldGrid Total Upkeep
CVE-2024-1692BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.13 - Authenticated(Contributor+) Stored Cross-Site Scripting via…BoldGrid Easy SEO – Simple and Effective SEO
CVE-2024-13907Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+)…BoldGrid
CVE-2024-12365W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgeryboldgrid W3 Total Cache
CVE-2024-12008W3 Total Cache <= 2.8.1 Information Exposure via Log Filesboldgrid W3 Total Cache
CVE-2024-12006W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions…boldgrid W3 Total Cache
CVE-2024-0386weForms <= 1.6.21 - Unauthenticated Stored Cross-Site Scripting via Refererboldgrid weForms – Easy Drag & Drop Contact Form Builder…
CVE-2023-5359W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintextboldgrid W3 Total Cache
CVE-2023-25480WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.24.1 is vulnerable to Cross Site…BoldGrid – Visual Drag and Drop Editor
CVE-2022-4932Total Upkeep <= 1.14.13 - Missing Authorization to Authenticated (Subscriber+) Information DisclosureBoldGrid
CVE-2021-24452W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context)BoldGrid W3 Total Cache
CVE-2021-24436W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context)BoldGrid W3 Total Cache
CVE-2021-24427W3 Total Cache < 2.1.3 - Authenticated Stored XSSBoldGrid W3 Total Cache
CVE-2020-36848Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup DownloadBoldGrid

52 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.