VulnSea

boldthemes has 4 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.4 (medium). The most common weakness class is CWE-79 (4). Most affected products: Bold Page Builder (2), Bold Timeline Lite (1), bold-page-builder (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.4
Publish → KEV
Last 90 days
3 prev 0

Weakness classes

Products

  • Bold Page Builder 2
  • Bold Timeline Lite 1
  • bold-page-builder 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

boldthemes vulnerabilities

CVEs affecting boldthemes, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-5920Medium· 6.4
6d ago

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6. This is due to a bypassable secur…

Sunlitboldthemes · Bold Page BuilderEPSS 0.23%via NVD
CVE-2026-62110Medium· 6.5
1w ago

WordPress Bold Page Builder plugin <= 5.9.9 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.

Sunlitboldthemes · bold-page-builderEPSS 0.16%via CVEORG
CVE-2026-7438Medium· 6.4
1w ago

The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient…

The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient…

Sunlitboldthemes · Bold Timeline LiteEPSS 0.21%via NVD
CVE-2025-15267Medium· 6.4
7mo ago

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escapin…

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escapin…

Sunlitboldthemes · Bold Page BuilderEPSS 0.26%via NVD
boldthemes vulnerabilities (CVEs) · VulnSea