enfold

enfold has 12 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2026; all 12 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high. 2026 was the busiest year with 3 disclosures.

The most common weakness is Cross-Site Scripting, behind 8 of the records (67%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Improper Access Control.

Every one of the 12 issues recorded for enfold has a vendor fix available, so running the current release closes all known holes.

7 independent researchers contributed these findings, most of them (3) reported by João Pedro Soares de Alcântara.

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

12

Get automatic notifications for all enfold vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2014-7297

Enfold < 3.0.1 - Unspecified Vulnerability

Read the full analysis

Vulnerability Records

12 records
2026-09-03 00:00CVE-2026-84815
7.2
High
Rafie MuhammadYes
2026-06-01 00:00CVE-2026-48869
6.1
Medium
João Pedro Soares de AlcântaraYes
2026-01-20 00:00CVE-2025-68900
6.4
Medium
João Pedro Soares de AlcântaraYes
2025-10-21 00:00CVE-2025-66053
6.4
Medium
João Pedro Soares de AlcântaraYes
2025-02-24 00:00CVE-2024-13693
5.3
Medium
mikemyersYes
2025-02-24 00:00CVE-2024-13695
6.4
Medium
mikemyersYes
2024-08-29 14:54CVE-2024-5061
6.4
Medium
stealthcopterYes
2024-06-20 00:00CVE-2024-37199
6.1
Medium
tomYes
2023-11-23 00:00CVE-2023-38400
6.1
Medium
Rafie MuhammadYes
2021-10-18 00:00CVE-2021-24719
6.1
Medium
Francisco Díaz-Pache AlonsoYes
Showing 1–10 of 12 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C