CVE-2026-32454

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Avada Core fusion-core allows DOM-Based XSS.This issue affects Avada Core: from n/a through < 5.15.0.
Configurations

No configuration.

History

16 Mar 2026, 14:53

Type Values Removed Values Added
Summary
  • (es) Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en ThemeFusion Avada Core fusion-core permite XSS basado en DOM. Este problema afecta a Avada Core: desde n/a hasta &lt; 5.15.0.

13 Mar 2026, 19:55

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-13 19:55

Updated : 2026-04-22 21:30


NVD link : CVE-2026-32454

Mitre link : CVE-2026-32454

CVE.ORG link : CVE-2026-32454


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')