VulnSea

BdThemes has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 3. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (5). Most affected products: bdthemes-element-pack-lite (3), Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator (1), bdthemes-prime-slider-lite (1).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
6 prev 0

Weakness classes

Products

  • bdthemes-element-pack-lite 3
  • Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator 1
  • bdthemes-prime-slider-lite 1
  • live-copy-paste 1
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

BdThemes vulnerabilities

CVEs affecting BdThemes, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-105875Medium· 6.5
today

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Stored XSS.This issue affects Prime Slider – Addons For …

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Stored XSS.This issue affects Prime Slider – Addons For …

▾ SunlitBdThemes · bdthemes-prime-slider-litevia NVD
CVE-2026-105873Medium· 6.5
today

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: f…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: f…

▾ SunlitBdThemes · bdthemes-element-pack-litevia NVD
CVE-2026-105871Medium· 6.5
today

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: f…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: f…

▾ SunlitBdThemes · bdthemes-element-pack-litevia NVD
CVE-2026-93527High· 8.5
2w ago

Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.

Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.

▾ Twilightbdthemes · live-copy-pasteEPSS 0.21%via NVD
CVE-2026-92991Medium· 5.4
2w ago

The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping

The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can compromise the Sigmative…

▾ Sunlitbdthemes · Live Copy Paste for Elementor – Cross Domain Copy Paste & Page DuplicatorEPSS 0.43%via NVD
CVE-2026-66574Medium· 6.5
2w ago

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

▾ Sunlitbdthemes · bdthemes-element-pack-liteEPSS 0.22%via NVD
BdThemes vulnerabilities (CVEs) · VulnSea