CVEs we hold for Uxper
Records whose assigning authority named Uxper as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-65525WordPress Civi Framework plugin <= 2.2.0 - Broken Access Control vulnerabilityuxper Civi Framework
CVE-2026-57794WordPress Golo Framework plugin <= 1.7.3 - Local File Inclusion vulnerabilityuxper Golo Framework
CVE-2026-28150WordPress Golo Framework plugin < 1.7.5 - Local File Inclusion vulnerabilityuxper Golo Framework
CVE-2026-23973WordPress Golo theme < 1.7.5 - Reflected Cross Site Scripting (XSS) vulnerabilityuxper Golo
CVE-2025-49892WordPress Uxper Booking Plugin <= 1.3.3 - Local File Inclusion VulnerabilityUxper Booking
CVE-2025-49511WordPress Civi Framework plugin <= 2.1.6 - Cross Site Request Forgery (CSRF) to User Deactivation vulnerabilityuxper Civi Framework
CVE-2025-4797Golo <= 1.7.0 - Authentication Bypass to Account Takeoveruxper Golo - City Travel Guide WordPress Theme
CVE-2025-4606Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account…uxper Sala - Startup & SaaS WordPress Theme
CVE-2024-13773Civi - Job Board & Freelance Marketplace WordPress Theme <= 2.1.4 - Sensitive Information Exposureuxper Civi - Job Board & Freelance Marketplace WordPress…
CVE-2024-13772Civi - Job Board & Freelance Marketplace WordPress Theme <= 2.1.6.1 - Authentication Bypassuxper Civi - Job Board & Freelance Marketplace WordPress…
CVE-2024-13771Civi - Job Board & Freelance Marketplace WordPress Theme <= 2.1.4 - Authentication Bypass via Password Updateuxper Civi - Job Board & Freelance Marketplace WordPress…
CVE-2024-12876Golo - Directory & Listing, Travel WordPress Theme <= 1.6.10 - Missing Authorization to Privilege Escalation via…uxper Golo - City Travel Guide WordPress Theme
33 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.