Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
301 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.64% | — | King-theme Page Builder Kingcomposer | 7/6/2023 | 17/6/2026 | The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in versions before 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever… | |
| Modificada | Alta (8.8) | 1.5% | — | King-theme Page Builder King Composer | 7/6/2023 | 17/6/2026 | The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_bulk_action' function in the 'kingcomposer/includes/kc.extensions.php' file. This makes it possible for authenticated users with author level permissions and above to… | |
| Modificada | Alta (8.8) | 1.2% | — | King-theme Page Builder Kingcomposer | 7/6/2023 | 17/6/2026 | The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in the '/wp-admin/index.php' page. This makes it possible for authenticated attackers to change arbitrary WordPress options, delete arbitrary… | |
| Modificada | Media (4.3) | 0.21% | — | Page Builder With Image MAP BY Azexo | 3/6/2023 | 17/6/2026 | The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. This is due to missing or incorrect nonce validation on the 'azh_save' function. This makes it possible for unauthenticated attackers to update the post content and inject malicious… | |
| Modificada | Media (4.3) | 0.50% | — | Page Builder With Image MAP BY Azexo | 3/6/2023 | 17/6/2026 | The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'azh_add_post' function in versions up to, and including, 1.27.133. This makes it possible for authenticated attackers to create a post with any post type and post status. | |
| Modificada | Alta (8.8) | 0.32% | — | Page Builder With Image MAP BY Azexo | 3/6/2023 | 17/6/2026 | The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. This is due to missing or incorrect nonce validation on the 'azh_add_post', 'azh_duplicate_post', 'azh_update_post' and 'azh_remove_post' functions. This makes it possible for… | |
| Modificada | Media (5.4) | 0.48% | — | Page Builder With Image MAP BY Azexo | 3/6/2023 | 17/6/2026 | The Page Builder by AZEXO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'azh_post' shortcode in versions up to, and including, 1.27.133 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages… | |
| Modificada | Media (4.8) | 0.39% | — | White Label Branding FOR Elementor Page Builder Project White Label Branding FOR Elementor Page Builder | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page Builder plugin <= 1.0.2 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Mega Addons FOR Wpbakery Page Builder | 8/5/2023 | 17/6/2026 | The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Ultimate Carousel FOR Wpbakery Page Builder | 8/5/2023 | 17/6/2026 | The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.5) | 0.90% | — | Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder | 17/4/2023 | 17/6/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks | |
| Modificada | Media (5.4) | 0.44% | — | Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder | 17/4/2023 | 17/6/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored… | |
| Modificada | Media (5.4) | 0.38% | — | Material Design Icons FOR Page Builders Project Material Design Icons FOR Page Builders | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Image Over Image FOR Wpbakery Page Builder Project Image Over Image FOR Wpbakery Page Builder | 3/4/2023 | 17/6/2026 | The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.38% | — | Webdevocean Image Hover Effects FOR Wpbakery Page Builder | 30/3/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions. | |
| Modificada | Media (4.3) | 0.28% | — | Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks | 27/3/2023 | 17/6/2026 | The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Alta (8.8) | 0.27% | — | Voidcoders Void Contact Form 7 Widget FOR Elementor Page Builder | 13/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions. | |
| Modificada | Baja (3.7) | 0.46% | — | Ibexa CommerceIbexa Digital Experience PlatformIbexa EZ PlatformIbexa Ezplatform-page-builder+3 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack. | |
| Analizada | Media (5.4) | 0.39% | — | Blueastral Page Builder\ | 21/2/2023 | 17/6/2026 | The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 0.26% | — | Material Design Icons FOR Page Builders Project Material Design Icons FOR Page Builders | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions. | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Wprealize Extensive VC Addons FOR Wpbakery Page Builder | 13/2/2023 | 17/6/2026 | The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE… | |
| Modificada | Media (5.4) | 0.47% | — | Pluginops Landing Page Builder | 23/1/2023 | 17/6/2026 | The Landing Page Builder WordPress plugin before 1.4.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Media (6.5) | 0.72% | — | Topdigitaltrends Mega Addons FOR Wpbakery Page Builder | 14/12/2022 | 17/6/2026 | The Mega Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the vc_saving_data function in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update the plugin's settings. | |
| Modificada | Media (4.8) | 0.49% | — | Themeum WP Page Builder | 5/12/2022 | 17/6/2026 | The WP Page Builder WordPress plugin through 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.4) | 0.45% | — | Themeum WP Page Builder | 18/11/2022 | 17/6/2026 | Multiple Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerabilities in WP Page Builder plugin <= 1.2.6 on WordPress. |