Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows Reflected XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.15.0.8.
We have discovered 235 live websites that are affected by CVE-2026-57816.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 235 live websites (100% of Funnel Builder install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 15 versions ( 83% of all versions) |
| 119 websites | |
| 14 websites | |
| 10 websites | |
| 9 websites | |
| 9 websites | |
| 5 websites | |
| 5 websites | |
| 5 websites | |
| 5 websites | |
| 5 websites |
| .com | 148 websites |
| .nl | 8 websites |
| .co.uk | 6 websites |
| .org | 6 websites |
| .fr | 6 websites |
| .pl | 5 websites |
| .net | 3 websites |
| .it | 3 websites |
| .com.au | 3 websites |
| .co | 2 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | **,*** | ||
| ********************.com | **,*** | ||
| *************.net | ***,*** | ||
| *********.com | ***,*** | ||
| ***********.com | ***,*** | ||
| ******.nl | ***,*** | ||
| ********.com | ***,*** | ||
| *****************.com | ***,*** | ||
| *************.com | *,***,*** | ||
| ********************.com | *,***,*** |
FAQ