Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

1426 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (10)——Payloadcms Plugin Form BuilderAI6/10/20266/10/2026
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Pendiente de análisisMedia (5.3)0.29%—Joomshaper SP Page Builder PROAI5/10/20266/10/2026
Joomla Extension - joomshaper.com - Reflected XSS in the Dynamic Content Filter addon in SP Page Builder Pro 3.0.0 - 5.6.1p2 - The slider minimum and maximum values are taken from the dc_filter_<fieldId> request parameter, split on the delimiter "l-r", HTML-escaped inside the data-value attribute, and then echoed…
AplazadaAlta (7.5)0.24%—Stylemixthemes Cost Calculator BuilderAI4/10/20266/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
AplazadaCrítica (9.1)0.53%—Fastlinemedia Beaver BuilderAI3/10/20266/10/2026
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.…
AplazadaAlta (8.8)0.28%—Kubio AI Page BuilderAI3/10/20266/10/2026
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before…
AplazadaMedia (6.8)0.24%—Kubio AI Page BuilderAI3/10/20266/10/2026
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator…
AplazadaMedia (6.5)0.27%—Fastlinemedia Beaver BuilderAI3/10/20266/10/2026
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaAlta (7.2)0.24%—Crocoblock JetformbuilderAI2/10/20263/10/2026
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaAlta (7.2)0.31%—Kubio AI Page BuilderAI2/10/20263/10/2026
The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaAlta (8.5)0.21%—Villatheme WOO Product BuilderAI1/10/20261/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a…
AplazadaAlta (7.2)0.30%—Siteorigin Page BuilderAI30/9/202630/9/2026
Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
AplazadaAlta (7.1)0.15%—Crocoblock JetformbuilderAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
AplazadaAlta (7.1)0.15%—Boldgrid Post AND Page BuilderAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
AplazadaMedia (6.5)0.13%—Visualcomposer Visual Composer Website BuilderAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions.
AplazadaAlta (8.8)0.36%—Themify BuilderAI30/9/202630/9/2026
Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.
AplazadaMedia (6.5)0.21%—Cozmoslabs Profile BuilderAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible…
AplazadaAlta (7.2)0.26%—User Profile BuilderAI25/9/202625/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.2)0.27%—Themify BuilderAI25/9/202625/9/2026
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaMedia (6.4)0.20%—Codeselling User Profile BuilderAI25/9/202625/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.1)0.21%—Crocoblock JetformbuilderAI25/9/202625/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for…