Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 1/4/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows DOM-Based XSS.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a before 3.21.4. | |
| Aplazada | Media (4.3) | 0.26% | — | Cozmoslabs User Profile BuilderAI | 31/3/2026 | 25/7/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on a user controlled key. This makes it… | |
| Aplazada | Media (6.5) | 0.22% | — | Extendthemes Kubio AI Page BuilderAI | 31/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder allows Stored XSS.This issue affects Kubio AI Page Builder: from n/a through 2.7.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Themefusion Fusion BuilderAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder fusion-builder allows Reflected XSS.This issue affects Fusion Builder: from n/a through < 3.15.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Themehunk Contact Form AND Lead Form Elementor BuilderAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder allows Stored XSS.This issue affects Contact Form & Lead Form Elementor Builder: from n/a through <= 2.0.1. | |
| Aplazada | Crítica (9.9) | 0.52% | — | Crocoblock JetformbuilderAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1. | |
| Aplazada | Alta (7.1) | 0.18% | — | Faq-builder-aysAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro FAQ Builder AYS faq-builder-ays allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FAQ Builder AYS: from n/a through <= 1.8.2. | |
| Aplazada | Alta (7.5) | 0.38% | — | Loopus WP Cost Estimation AND Payment Forms BuilderAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in loopus WP Cost Estimation & Payment Forms Builder WP_Estimation_Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through < 10.3.0. | |
| Aplazada | Alta (7.5) | 0.57% | — | Crocoblock JetformbuilderAI | 21/3/2026 | 17/6/2026 | The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating that the path belongs… | |
| Aplazada | Media (6.4) | 0.35% | — | Ecover Builder FOR DummiesAI | 21/3/2026 | 17/6/2026 | The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'ecover' shortcode in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping on the user-supplied 'id' shortcode attribute. This makes it… | |
| Aplazada | Media (5.3) | 0.40% | — | Eshot Form BuilderAI | 21/3/2026 | 17/6/2026 | The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.2. The eshot_form_builder_get_account_data() function is registered as a wp_ajax_ AJAX handler accessible to all authenticated users. The function lacks any capability check (e.g.,… | |
| Aplazada | Media (6.5) | 0.28% | — | Appcheap APP BuilderAI | 21/3/2026 | 17/6/2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.10. This is due to the `verify_role()` function in `AuthTrails.php` explicitly whitelisting the `wcfm_vendor` role alongside `subscriber` and `customer`,… | |
| Aplazada | Crítica (9.8) | 0.59% | — | Thimpress BuilderpressAIPHPAI | 19/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress builderpress allows PHP Local File Inclusion.This issue affects BuilderPress: from n/a through <= 2.0.1. | |
| Aplazada | Alta (7.1) | 0.19% | — | Tagdiv Opt-in BuilderAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows Reflected XSS.This issue affects tagDiv Opt-In Builder: from n/a through <= 1.7.3. | |
| Aplazada | Media (5.3) | 0.48% | — | Instant Popup BuilderAI | 19/3/2026 | 17/6/2026 | The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all versions up to and including 1.1.7. This is due to the handle_email_verification_page() function constructing a shortcode string from user-supplied GET parameters (token, email) and passing it to… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Cozmoslabs Profile Builder PROAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0. | |
| Aplazada | Media (5.3) | 0.29% | — | Themefusion Fusion BuilderAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fusion Builder: from n/a through < 3.15.0. | |
| Aplazada | Media (6.5) | 0.25% | — | Themefusion Fusion BuilderAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fusion Builder: from n/a through < 3.15.0. | |
| Aplazada | Media (5.3) | 0.26% | — | Xpro Addons FOR Beaver Builder LiteAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Xpro Xpro Addons For Beaver Builder – Lite xpro-addons-beaver-builder-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xpro Addons For Beaver Builder – Lite: from n/a through <= 1.5.6. | |
| Aplazada | Media (5.3) | 0.33% | — | Radiustheme ShopbuilderAI | 13/3/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Retrieve Embedded Sensitive Data.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through <= 3.2.4. | |
| Aplazada | Alta (7.2) | 0.24% | — | Responsive Contact Form BuilderAI | 11/3/2026 | 17/6/2026 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in the lfb_lead_sanitize() function which omits certain field types from… | |
| Aplazada | Media (6.5) | 0.31% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through <= 3.21.1. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Builderall Builder FOR WordpressAI | 5/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Code Injection.This issue affects Builderall Builder for WordPress: from n/a through <= 3.0.1. | |
| Aplazada | Media (4.4) | 0.26% | — | TaskbuilderAI | 4/3/2026 | 17/6/2026 | The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Alta (8.8) | 0.92% | — | Siteorigin Page BuilderAI | 3/3/2026 | 17/6/2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate_template() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server,… |