Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elementor Elementor Pro allows Reflected XSS.This issue affects Elementor Pro: from n/a through 3.21.2.
We have discovered 315,994 live websites that are affected by CVE-2024-35656.
| Product | |
| Category | Landing Page Builders |
| Vulnerable Domains | 315,994 live websites (25% of Elementor Pro install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 189 versions ( 74% of all versions) |
| 79,960 websites | |
| 29,064 websites | |
| 17,438 websites | |
| 15,108 websites | |
| 12,993 websites | |
| 12,377 websites | |
| 11,139 websites | |
| 10,703 websites | |
| 7,896 websites | |
| 7,838 websites |
| .com | 126,420 websites |
| .com.br | 16,422 websites |
| .de | 15,586 websites |
| .org | 11,316 websites |
| .it | 8,903 websites |
| .ru | 8,359 websites |
| .co.uk | 7,168 websites |
| .nl | 7,020 websites |
| .net | 6,485 websites |
| .fr | 6,144 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **************.de | *** | ||
| ***.***.ca | *,*** | ||
| ******.com | *,*** | ||
| **********.com | *,*** | ||
| ******.com | *,*** | ||
| ******************.org | *,*** | ||
| *********.com | *,*** | ||
| **********.com | *,*** | ||
| ********.com | *,*** | ||
| ***************.org | *,*** |
FAQ