Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
1951 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | Blog Posts AND Category Filter FOR ElementorAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Piotnet Addons FOR ElementorAI | 6/10/2026 | 6/10/2026 | Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Crocoblock JetelementsAI | 6/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through 2.9.2.2. | |
| Aplazada | Media (6.5) | 0.24% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 5/10/2026 | 6/10/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Parameter Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Aplazada | Media (6.5) | 0.16% | — | Leap13 Premium Addons FOR ElementorAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeapWorx Premium Addons for Elementor premium-addons-for-elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.11.109. | |
| Aplazada | Crítica (9.3) | 0.25% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 4/10/2026 | 6/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Aplazada | Alta (7.1) | 0.15% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 4/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,… | |
| Aplazada | Alta (7.1) | 0.15% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,… | |
| Aplazada | Media (6.3) | 0.18% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level… | |
| Aplazada | Media (6.8) | 0.22% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and to retrieve non-public content, when a related widget option is set away from its default. | |
| Aplazada | Media (6.6) | 0.42% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress… | |
| Aplazada | Media (5.4) | 0.24% | — | JEG KIT FOR ElementorAI | 3/10/2026 | 6/10/2026 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.4) | 0.18% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 2/10/2026 | 2/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level… | |
| Aplazada | Media (6.8) | 0.24% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 2/10/2026 | 2/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered. | |
| Aplazada | Media (5.3) | 0.19% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates):… | |
| Aplazada | Alta (8.5) | 0.21% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Aplazada | Media (6.5) | 0.13% | — | Wpmet Elementskit LiteAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6. | |
| Aplazada | Media (6.5) | 0.13% | — | Wpmet Elementskit LiteAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6. | |
| Aplazada | Media (6.5) | 0.13% | — | Wpdeveloper Essential Addons FOR ElementorAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 6.8.4. | |
| Aplazada | Alta (7.2) | 0.19% | — | Lastudio Element KITAI | 1/10/2026 | 1/10/2026 | Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2. | |
| Aplazada | Media (6.5) | 0.18% | — | Qodeinteractive QI Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions. | |
| Aplazada | Media (6.5) | 0.16% | — | Leap13 Premium Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | |
| Aplazada | Media (6.4) | 0.16% | — | Htmega HT Mega Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table 'display_options' Setting in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.24% | — | Repeater Fields FOR Elementor FormsAI | 25/9/2026 | 25/9/2026 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (8.8) | 0.13% | — | ElementorAI | 25/9/2026 | 25/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1. |