Qodeinteractive
Qodeinteractive QI Blocks: vulnerabilidades y CVE
Qodeinteractive QI Blocks tiene 10 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses4
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-10096 | Media (4.3) | 0.34% | — | 1 jul 2026 | The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' parameter due to missing validation on a user controlled key. This makes… |
| CVE-2025-12182 | Media (4.3) | 0.22% | — | 15 nov 2025 | The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up to, and including, 1.4.3. This is due to the plugin… |
| CVE-2025-64383 | Media (6.5) | 0.16% | — | 13 nov 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks allows Stored XSS.This issue affects Qi Blocks: from n/a through <= 1.4.3. |
| CVE-2025-12180 | Media (4.3) | 0.22% | — | 1 nov 2025 | The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin storing arbitrary CSS styles submitted via the… |
| CVE-2025-1627 | Media (5.4) | 0.24% | — | 19 may 2025 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and… |
| CVE-2025-1626 | Media (5.4) | 0.24% | — | 19 may 2025 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the… |
| CVE-2025-1625 | Media (5.4) | 0.28% | — | 19 may 2025 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor… |
| CVE-2024-49690 | Alta (8.8) | 0.56% | — | 23 oct 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.2. |
| CVE-2024-38712 | Media (5.4) | 0.26% | — | 20 jul 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3. |
| CVE-2024-5221 | Media (5.4) | 0.25% | — | 6 jun 2024 | The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This… |