Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1033 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.49% | — | Crocoblock JetreviewsAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetReviews jet-reviews allows PHP Local File Inclusion.This issue affects JetReviews: from n/a through <= 3.0.0. | |
| Aplazada | Media (5.3) | 0.27% | — | Bdthemes ZoloblocksAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in bdthemes ZoloBlocks zoloblocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ZoloBlocks: from n/a through <= 2.3.11. | |
| Aplazada | Media (4.3) | 0.22% | — | Moodle Openai Chat BlockAI | 21/10/2025 | 5/7/2026 | Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in /blocks/openai_chat/api/completion.php. An authenticated student can impersonate another user's block (e.g., administrator) and send… | |
| Aplazada | Media (5.8) | 0.27% | — | Wikimedia Mediawiki Globalblocking ExtensionAI | 20/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki GlobalBlocking extension allows Stored XSS.This issue affects MediaWiki GlobalBlocking extension: 1.43, 1.44. | |
| Aplazada | Media (6.4) | 0.25% | — | Wpdeveloper Essential BlocksAI | 18/10/2025 | 17/6/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.30% | — | Wpdeveloper Essential BlocksAI | 18/10/2025 | 17/6/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for authenticated attackers, with Author-level access and… | |
| Aplazada | Media (4.3) | 0.17% | — | Page BlocksAI | 11/10/2025 | 30/9/2026 | The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the admin_process_widget_page_change function. This makes it possible for unauthenticated attackers to modify widget page block… | |
| Aplazada | Media (6.4) | 0.25% | — | Zelabs ZoloblocksAI | 1/10/2025 | 17/6/2026 | The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versions up to, and including, 2.3.10. This is due to insufficient input sanitization and output escaping on user-supplied attributes within multiple block components including Google Maps markers,… | |
| Aplazada | Media (4) | 0.30% | — | Block FOR MailchimpAI | 1/10/2025 | 1/10/2026 | The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.12 via the mcbSubmit_Form_Data(). This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from… | |
| Aplazada | Media (6.4) | 0.24% | — | Nexa BlocksAI | 30/9/2025 | 17/6/2026 | The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Google Maps widget in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.12% | — | Taraprasad Swain Htaccess IP BlockerAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Taraprasad Swain HTACCESS IP Blocker htaccess-ip-blocker allows Stored XSS.This issue affects HTACCESS IP Blocker: from n/a through <= 1.0. | |
| Aplazada | Media (5.4) | 0.21% | — | Bdthemes ZoloblocksAI | 26/9/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in bdthemes ZoloBlocks zoloblocks allows Server Side Request Forgery.This issue affects ZoloBlocks: from n/a through <= 2.3.11. | |
| Aplazada | Media (6.5) | 0.21% | — | Sktthemes SKT BlocksAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a through <= 2.6. | |
| Aplazada | Media (4.3) | 0.27% | — | Stackable-ultimate-gutenberg-blocksAI | 26/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Retrieve Embedded Sensitive Data.This issue affects Stackable: from n/a through <= 3.18.1. | |
| Aplazada | Media (4.3) | 0.24% | — | Stackable-ultimate-gutenberg-blocksAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stackable: from n/a through <= 3.18.1. | |
| Aplazada | Media (4.3) | 0.25% | — | Hashthemes Smart BlocksAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in hashthemes Smart Blocks smart-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Blocks: from n/a through <= 2.4. | |
| Aplazada | Media (4.3) | 0.25% | — | Thedevoice Lazy BlocksAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in nK Lazy Blocks lazy-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lazy Blocks: from n/a through <= 4.1.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Bdthemes ZoloblocksAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes ZoloBlocks zoloblocks allows DOM-Based XSS.This issue affects ZoloBlocks: from n/a through <= 2.3.12. | |
| Aplazada | Media (5.3) | 0.27% | — | Sumit Singh Classic Widgets With Block Based WidgetsAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Sumit Singh Classic Widgets with Block-based Widgets classic-widgets-with-block-based-widgets allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classic Widgets with Block-based Widgets: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.3) | 0.36% | — | Blocksera Image Hover Effects Addon FOR ElementorAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Blocksera Image Hover Effects – Elementor Addon image-hover-effects-addon-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Hover Effects – Elementor Addon: from n/a through <= 1.4.4. | |
| Aplazada | Media (6.5) | 0.27% | — | Ataur R Gutenkit Blocks AddonAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit gutenkit-blocks-addon allows Stored XSS.This issue affects GutenKit: from n/a through <= 2.4.2. | |
| Aplazada | Media (5.3) | 0.24% | — | Cozythemes Cozy BlocksAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CozyThemes Cozy Blocks cozy-addons allows Code Injection.This issue affects Cozy Blocks: from n/a through <= 2.1.29. | |
| Aplazada | Media (5) | 0.26% | — | Christiaan Pieterse Maxi BlocksAI | 22/9/2025 | 30/9/2026 | Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MaxiBlocks: from n/a through <= 2.1.3. | |
| Aplazada | Media (5.9) | 0.24% | — | Ricky Dawn BOT Block Stop Spam Google Analytics ReferralsAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ricky Dawn Bot Block – Stop Spam Referrals in Google Analytics bot-block-stop-spam-google-analytics-referrals allows Stored XSS.This issue affects Bot Block – Stop Spam Referrals in Google Analytics: from n/a through… | |
| Aplazada | Media (6.4) | 0.25% | — | Creativethemes Blocksy CompanionAI | 17/9/2025 | 17/6/2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newsletter_subscribe shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… |