live_composer_free_wordpress_website_builder vulnerabilities
CVEs whose affected-version data names the live_composer_free_wordpress_website_builder package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-16778Medium· 6.4The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up to, and including, 2.1.21 due to insufficient in…
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up to, and including, 2.1.21 due to insufficient in…
▾ Sunlitlivecomposer · Live Composer – Free WordPress Website BuilderEPSS 0.22%via NVD
CVE-2026-16502High· 8.8The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated …
▾ Twilightlivecomposer · Live Composer – Free WordPress Website BuilderEPSS 0.47%via NVD