Known Vulnerabilities for Visual Composer Website Builder by Visualcomposer
Listed below are 6 of the newest known vulnerabilities associated with "Visual Composer Website Builder" by "Visualcomposer".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-97262 json | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions. | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-65568 json | Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-62138 json | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions. | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-12227 json | The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2025-46254 json | Not Provided | 2025-04-22 | 2026-04-23 | |
| CVE-2024-35653 json | Not Provided | 2024-06-04 | 2026-04-23 | |
| CVE-2023-6880 json | Not Provided | 2024-03-13 | 2026-04-08 | |
| CVE-2022-2516 json | The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Titl... | 5.4 - MEDIUM | 2022-09-06 | 2022-09-13 |
| CVE-2022-2430 json | The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' fe... | 5.4 - MEDIUM | 2022-09-06 | 2022-09-12 |
| CVE-2020-36722 json | Not Provided | 2023-06-07 | 2026-04-08 |