cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcornerstone cornerstone

Direction: ascending
Jun 07, 2024

Cornerstone # CVE-2024-28002

CVE, Research URL

CVE-2024-28002

Application

Cornerstone

Date
Mar 28, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Archetyped Cornerstone allows Reflected XSS.This issue affects Cornerstone: from n/a through 0.8.0.
Affected versions
max 0.8.1.
Status
vulnerable

Cornerstone # CVE-2024-32570

CVE, Research URL

CVE-2024-32570

Application

Cornerstone

Date
Apr 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Archetyped Cornerstone allows Reflected XSS.This issue affects Cornerstone: from n/a through 0.8.0.
Affected versions
max 0.8.1.
Status
vulnerable
Jan 10, 2026

Cornerstone # CVE-2025-63072

CVE, Research URL

CVE-2025-63072

Application

Cornerstone

Date
Dec 09, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in THEMECO Cornerstone cornerstone allows Stored XSS.This issue affects Cornerstone: from n/a through <= 7.7.3.
Affected versions
max 7.7.3.
Status
vulnerable
Jun 09, 2026

Cornerstone # CVE-2026-49113

CVE, Research URL

CVE-2026-49113

Application

Cornerstone

Date
Jun 17, 2026
Research Description
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
Affected versions
max 7.8.8.
Status
vulnerable
Jun 19, 2026

Cornerstone # CVE-2026-54185

CVE, Research URL

CVE-2026-54185

Application

Cornerstone

Date
Jun 17, 2026
Research Description
Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
Affected versions
max 7.8.8.
Status
vulnerable
Jun 26, 2026

Cornerstone # CVE-2026-9709

CVE, Research URL

CVE-2026-9709

Application

Cornerstone

Date
Jun 24, 2026
Research Description
The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of any other user, including roles, session token previews and stored billing/shipping fields. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free `cornerstone` Cornerstone WordPress plugin before 7.8.9 (v0.8.x) on the .org repository.
Affected versions
max 7.8.9.
Status
vulnerable

Cornerstone # CVE-2026-9710

CVE, Research URL

CVE-2026-9710

Application

Cornerstone

Date
Jun 24, 2026
Research Description
The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to every logged-in user on any wp-admin page, allowing any authenticated user to evaluate dynamic content tokens against arbitrary users and disclose their sensitive metadata including raw password hashes. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free `cornerstone` Cornerstone WordPress plugin before 7.8.8 (v0.8.x) on the .org repository.
Affected versions
max 7.8.8.
Status
vulnerable