CVE-2025-64354
Gutenberg
Minimum safe version
21.9.0
Update to 21.9.0 or later to address 9 fixable vulnerabilities
CVE-2024-37492
WordPress Gutenberg Plugin 12.9.0-18.0.0 is vulnerable to Cross Site Scripting (XSS)
Gutenberg 12.9.0 - 18.0.0 - Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block
Gutenberg < 16.8.1 - Contributor+ Stored XSS
CVE-2023-38000
Gutenberg < 14.3.1 - Multiple Stored XSS
WordPress Core < 5.9.2 & Gutenberg < 12.7.2 - Prototype Pollution via Block Editor
WordPress Core < 6.0.3 & Gutenberg < 14.3.1 - Authenticated Cross-Site Scripting in Various Blocks
WordPress Gutenberg plugin <= 14.3.0 - Multiple Stored Cross-Site Scripting (XSS) vulnerabilities
WordPress Gutenberg plugin <= 13.7.3 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress Gutenberg plugin <= 12.7.1 - Stored Cross-Site Scripting (XSS) vulnerability