Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

301 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.36%—Topdigitaltrends Mega Addons FOR Wpbakery Page Builder23/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Topdigitaltrends Mega Addons For WPBakery Page Builder plugin <= 4.2.7 at WordPress.
ModificadaCrítica (9.8)0.85%—Justsystems Atok Medical 2Justsystems Atok Medical 3Justsystems Atok PRO 3Justsystems Atok PRO 4+5616/8/202217/6/2026
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of…
ModificadaMedia (4.8)1.1%—Bold-themes Bold Page Builder11/7/202217/6/2026
The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
ModificadaMedia (6.1)0.80%—Presscustomizr Nimble Page Builder11/4/202217/6/2026
The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (8.8)1.7%—Brizy-page Builder14/10/202117/6/2026
The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot AJAX action. The file would be named using the id parameter, which could be prepended with "../" to perform directory traversal, and the…
ModificadaMedia (6.5)0.75%—Brizy-page Builder14/10/202117/6/2026
The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor. An identical issue was found by another researcher in Brizy <=…
ModificadaMedia (5.4)0.63%—Brizy-page Builder14/10/202117/6/2026
The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying the request sent to update the page via the brizy_update_item AJAX action and adding JavaScript to the data parameter,…
ModificadaAlta (8.8)8.2%—Bold-themes Bold Page Builder30/8/202117/6/2026
The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not contain a suitable gadget to fully exploit the issue, other…
ModificadaMedia (6.5)0.94%—Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard6/5/202117/6/2026
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).
ModificadaMedia (5.4)0.70%—Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard6/5/202117/6/2026
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.
ModificadaMedia (5.4)0.59%—Posimyth THE Plus Addons FOR Elementor Page Builder Lite5/5/202117/6/2026
The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
ModificadaMedia (5.4)0.66%—Themeum WP Page Builder5/4/202117/6/2026
The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML, including JavaScript, into pages via the “Raw HTML” widget and the “Custom HTML” widgets (though the custom HTML widget requires sending a crafted request - it appears that this widget uses some…
ModificadaMedia (4.3)0.69%—Themeum WP Page Builder5/4/202117/6/2026
By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically blocked from editing posts and pages.
ModificadaMedia (5.4)0.70%—Wpbakery Page Builder16/11/202017/6/2026
The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.
ModificadaMedia (5.4)0.70%—Elementor Page Builder16/9/202017/6/2026
A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.
ModificadaMedia (5.4)0.76%—Elementor Page Builder5/6/202017/6/2026
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
ModificadaMedia (5.4)0.76%—Elementor Page Builder5/6/202017/6/2026
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.
ModificadaAlta (8.8)0.81%—Siteorigin Page Builder28/5/202017/6/2026
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the…
ModificadaAlta (8.8)0.81%—Siteorigin Page Builder28/5/202017/6/2026
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the…
ModificadaCrítica (9.9)8.6%—Elementor Page Builder17/5/202017/6/2026
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
ModificadaCrítica (9.9)3.1%—Elementor Page Builder22/4/202017/6/2026
An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.
ModificadaMedia (6.1)1.3%—Elementor Page Builder7/10/201917/6/2026
The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.
ModificadaAlta (8.8)1.4%—Elementor Page Builder10/9/201917/6/2026
The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.
ModificadaAlta (7.5)11%—Bold-themes Bold Page Builder30/8/201917/6/2026
The bold-page-builder plugin before 2.3.2 for WordPress has no protection against modifying settings and importing data.
ModificadaMedia (6.1)1.3%—Components FOR WP Bakery Page Builder Project Components FOR WP Bakery Page Builder29/8/201917/6/2026
The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
Orbitaley — Vulnerabilidades