CVEs we hold for Softaculous
Records whose assigning authority named Softaculous as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-59519WordPress FormLayer plugin <= 1.0.6 - Sensitive Data Exposure vulnerabilitySoftaculous FormLayer
CVE-2026-5114SpeedyCache <= 1.3.8 - Authenticated (Administrator+) Arbitrary File Readsoftaculous SpeedyCache – Cache, Optimization, Performance
CVE-2026-39469WordPress PageLayer plugin <= 2.0.8 - Sensitive Data Exposure vulnerabilitySoftaculous PageLayer
CVE-2026-3297Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site…softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2026-2509Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom…softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2026-2470Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2026-2442Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2025-9277SiteSEO – SEO Simplified <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Broken Regex Expressionsoftaculous SiteSEO – SEO Simplified
CVE-2025-4223Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url…softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2025-24573WordPress Pagelayer plugin <= 1.9.4 - Cross Site Scripting (XSS) vulnerabilitySoftaculous PageLayer
CVE-2025-2104Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated…softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2025-1926Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents…softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2025-13085SiteSEO – SEO Simplified <= 1.3.2 - Insecure Direct Object Reference to Sensitive Post Meta Disclosuresoftaculous SiteSEO – SEO Simplified
CVE-2025-12814SiteSEO – SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings Resetsoftaculous SiteSEO – SEO Simplified
CVE-2025-12367SiteSEO – SEO Simplified <= 1.3.1 - Missing Authorization to Authenticated (Author+) Plugin Settings Updatesoftaculous SiteSEO – SEO Simplified
CVE-2025-12366Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object…softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2025-10307Backuply – Backup, Restore, Migrate and Clone <= 1.4.8 - Authenticated (Admin+) Arbitrary File Deletionsoftaculous Backuply – Backup, Restore, Migrate and Clone
CVE-2024-8669Backuply – Backup, Restore, Migrate and Clone <= 1.3.4 - Authenticated (Admin+) SQL Injectionsoftaculous Backuply – Backup, Restore, Migrate and Clone
CVE-2024-7985FileOrganizer <= 1.0.9 - Authenticated (Subscriber+) Arbitrary File Uploadsoftaculous FileOrganizer – WordPress File Manager
CVE-2024-5599FileOrganizer <= 1.0.7 - Sensitive Information Exposure via Directory Listingsoftaculous FileOrganizer – WordPress File Manager
CVE-2024-43299WordPress SpeedyCache plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) vulnerabilitySoftaculous SpeedyCache
CVE-2024-2504Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site…softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2024-2324FileOrganizer and FileOrganizer Pro <= 1.0.6 - Authenticated Stored Cross-Site Scriptingsoftaculous FileOrganizer – WordPress File Manager
CVE-2024-2294Backuply – Backup, Restore, Migrate and Clone <= 1.2.7 - Authenticated (Admin+) Directory Traversalsoftaculous Backuply – Backup, Restore, Migrate and Clone
CVE-2024-2127Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site…softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2024-1590Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site…softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2024-13430Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure…softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2024-13427Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site…softaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2024-11010FileOrganizer <= 1.1.4 - Authenticated (Administrator+) Local JavaScript File Inclusionsoftaculous FileOrganizer – WordPress File Manager
CVE-2024-10097Loginizer Security and Loginizer <= 1.9.2 - Authentication Bypass via WordPress.com OAuth providersoftaculous Loginizer
CVE-2024-0842Backuply - Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of Servicesoftaculous Backuply – Backup, Restore, Migrate and Clone
CVE-2024-0697Backuply – Backup, Restore, Migrate and Clone <= 1.2.3 - Authenticated (Administrator+) Directory Traversalsoftaculous Backuply – Backup, Restore, Migrate and Clone
CVE-2023-6738PageLayer <= 1.7.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via meta fieldssoftaculous Page Builder: Pagelayer – Drag and Drop website…
CVE-2023-6598SpeedyCache <= 1.1.3 - Missing Authorization to Plugin Options Updatesoftaculous SpeedyCache – Cache, Optimization, Performance
CVE-2023-49746WordPress SpeedyCache Plugin <= 1.1.2 is vulnerable to Server Side Request Forgery (SSRF)Softaculous Team SpeedyCache – Cache, Optimization…
CVE-2023-41854WordPress wpCentral Plugin <= 1.5.7 is vulnerable to Cross Site Request Forgery (CSRF)Softaculous Ltd. wpCentral
CVE-2022-45084WordPress Loginizer Plugin <= 1.7.5 is vulnerable to Cross Site Scripting (XSS)Softaculous Loginizer
CVE-2022-45079WordPress Loginizer Plugin <= 1.7.5 is vulnerable to Cross Site Request Forgery (CSRF)Softaculous Loginizer
41 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.