Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.75% | — | Elementor Website Builder | 5/4/2021 | 17/6/2026 | In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified… | |
| Modificada | Media (5.4) | 0.75% | — | Elementor Website Builder | 5/4/2021 | 17/6/2026 | In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’… | |
| Modificada | Media (5.4) | 0.75% | — | Elementor Website Builder | 5/4/2021 | 17/6/2026 | In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’… | |
| Modificada | Media (5.4) | 0.75% | — | Elementor Website Builder | 5/4/2021 | 17/6/2026 | In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’… | |
| Modificada | Media (6.1) | 0.83% | — | Elementor Website Builder | 6/1/2021 | 17/6/2026 | The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads. | |
| Modificada | Crítica (9.8) | 1.7% | — | Websitebaker | 1/10/2020 | 17/6/2026 | WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. | |
| Modificada | Media (5.4) | 0.69% | — | Elementor Website Builder | 31/8/2020 | 17/6/2026 | An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field. | |
| Modificada | Media (6.5) | 0.99% | — | Elementor Website Builder | 21/8/2020 | 17/6/2026 | Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog. | |
| Modificada | Media (5.4) | 1.3% | — | Elementor Website Builder | 28/1/2020 | 17/6/2026 | The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user. | |
| Modificada | Crítica (9.8) | 1.7% | — | Elementor Website Builder | 22/1/2020 | 17/6/2026 | The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. | |
| Modificada | Alta (7.5) | 1.2% | — | Websitebaker | 21/1/2020 | 16/6/2026 | websitebaker prior to and including 2.8.1 has an authentication error in backup module. | |
| Modificada | Alta (8.8) | 0.50% | — | Websitebaker | 14/1/2020 | 16/6/2026 | A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions. | |
| Modificada | Alta (7.2) | 1.1% | — | Websitebaker | 14/1/2020 | 16/6/2026 | An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions. | |
| Modificada | Crítica (9.8) | 2.3% | — | Education Website Project Education Website | 19/6/2019 | 17/6/2026 | SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter. | |
| Modificada | Media (5.4) | 0.64% | — | Chartered Accountant \ Auditor Website Project | 6/6/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field. | |
| Modificada | Media (5.9) | 1.8% | — | Yarnpkg Website | 16/5/2019 | 17/6/2026 | The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with… | |
| Modificada | Media (6.5) | 1.4% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory. | |
| Modificada | Media (6.5) | 1.6% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field. | |
| Modificada | Media (5.4) | 0.65% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field. | |
| Modificada | Media (5.3) | 1.6% | — | Website Seller Script Project Website Seller Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file. | |
| Modificada | Media (6.5) | 0.94% | — | Auction Website Script Project Auction Website Script | 23/2/2019 | 17/6/2026 | PHP Scripts Mall Auction website script 2.0.4 allows parameter tampering of the payment amount. | |
| Modificada | Alta (8.8) | 0.50% | — | Universal Website Asthis | 30/12/2018 | 17/6/2026 | UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF. | |
| Modificada | Media (5.4) | 0.53% | — | Website Seller Script Project Website Seller Script | 28/12/2018 | 17/6/2026 | PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a Profile field such as Company Address, a related issue to CVE-2018-15896. | |
| Modificada | Media (6.1) | 0.68% | — | Phpscriptsmall Website Seller Script | 4/10/2018 | 17/6/2026 | PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has XSS via the Listings Search feature. | |
| Modificada | Media (6.5) | 1.1% | — | Website Seller Script Project Website Seller Script | 28/8/2018 | 17/6/2026 | PHP Scripts Mall Website Seller Script 2.0.5 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, Company Name, or Fax field, as demonstrated by crossPwn. |