Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Themefusion Fusion BuilderAI | 22/10/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder fusion-builder allows DOM-Based XSS.This issue affects Fusion Builder: from n/a through <= 3.13.2. | |
| Analizada | Media (5.4) | 0.23% | — | Wpbakery Page Builder | 18/10/2025 | 17/6/2026 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, 8.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.2) | 0.38% | — | 10webbuilder 10webmapbuilderAI | 18/10/2025 | 17/6/2026 | The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in versions up to, and including, 1.0.63 due to insufficient input sanitization and output escaping and a lack of capability checks. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Crítica (9.6) | 0.43% | — | Illia-builderAI | 17/10/2025 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users to send arbitrary requests to internal services via the API. An attacker can leverage this to enumerate open ports based on response discrepancies and interact with internal services. | |
| Analizada | Media (5.4) | 0.21% | — | Wpbakery Page Builder | 15/10/2025 | 17/6/2026 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to, and including, 8.6.1. This is due to insufficient restriction of allowed HTML tags and improper sanitization of user-supplied attributes in the font_container… | |
| Analizada | Media (5.4) | 0.21% | — | Wpbakery Page Builder | 15/10/2025 | 17/6/2026 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in all versions up to, and including, 8.6.1. This is due to insufficient input sanitization and output escaping of user-supplied JavaScript code in the Custom JS module. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.23% | — | Extendthemes Colibri Page BuilderAI | 11/10/2025 | 17/6/2026 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.39% | — | Popup Builder GamificationAI | 9/10/2025 | 17/6/2026 | The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.1.3. This is due to insufficient escaping on the 'id' parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Alta (8.1) | 0.31% | — | Stylemixthemes Cost Calculator BuilderAI | 4/10/2025 | 17/6/2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capability check on the get_cc_orders and update_order_status functions in all versions up to, and including, 3.5.32. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Alta (8.8) | 0.18% | — | TextbuilderAI | 3/10/2025 | 17/6/2026 | The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due to missing or incorrect nonce validation on the 'handleToken' function. This makes it possible for unauthenticated attackers to update a user's authorization token via a forged request granted they… | |
| Aplazada | Alta (7.7) | 0.42% | — | Seatheme BM Content BuilderAI | 26/9/2025 | 30/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder bm-builder allows Path Traversal.This issue affects BM Content Builder: from n/a through < 3.16.3.3. | |
| Aplazada | Baja (2.7) | 0.22% | — | Shopengine Elementor Woocommerce Builder AddonAI | 26/9/2025 | 17/6/2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.33% | — | Themify BuilderAI | 24/9/2025 | 25/9/2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.20% | — | Agency Dominion INC Fusion Page Builder Extension GalleryAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion Page Builder : Extension – Gallery fusion-extension-gallery allows Stored XSS.This issue affects Fusion Page Builder : Extension – Gallery: from n/a through <= 1.7.6. | |
| Aplazada | Media (6.5) | 0.21% | — | Guaven SQL Chart BuilderAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Guaven Labs SQL Chart Builder sql-chart-builder allows DOM-Based XSS.This issue affects SQL Chart Builder: from n/a through <= 2.3.7.2. | |
| Aplazada | Media (6.5) | 0.27% | — | HT Plugins HT Mega - Absolute Addons FOR Wpbakery Page BuilderAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega – Absolute Addons for WPBakery Page Builder ht-mega-for-wpbakery allows DOM-Based XSS.This issue affects HT Mega – Absolute Addons for WPBakery Page Builder: from n/a through <= 1.0.9. | |
| Aplazada | Media (5.4) | 0.26% | — | Kubio AI Page BuilderAI | 19/9/2025 | 17/6/2026 | The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the kubio-image-hub-install-plugin AJAX action in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Analizada | Media (6.5) | 0.41% | — | Dpgaspar Flask-appbuilder | 11/9/2025 | 17/6/2026 | Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to use OAuth, LDAP, or other non-database authentication methods, the password reset endpoint remains registered and accessible, despite not being displayed in the user interface. This allows an… | |
| Aplazada | Media (6.4) | 0.24% | — | Smart Table BuilderAI | 6/9/2025 | 17/6/2026 | The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Alta (7.1) | 0.19% | — | Beaver Builder Wordpress AssistantAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from n/a through <= 1.5.2. | |
| Analizada | Media (6.1) | 0.22% | — | Fastlinemedia Beaver Builder | 28/8/2025 | 17/6/2026 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'fl_builder' parameter in all versions up to, and including, 2.9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.5) | 0.23% | — | Xpro Theme BuilderAI | 27/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Xpro Xpro Theme Builder xpro-theme-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xpro Theme Builder: from n/a through <= 1.2.9. | |
| Aplazada | Media (6.5) | 0.17% | — | Bold-themes Bold Page BuilderAI | 27/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through <= 5.4.3. | |
| Aplazada | Media (5.5) | 0.18% | — | Delta Electronics EIP BuilderAI | 26/8/2025 | 17/6/2026 | Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability. | |
| Aplazada | Media (4.3) | 0.20% | — | Wpsoul Greenshift Animation AND Page Builder BlocksAI | 22/8/2025 | 17/6/2026 | Missing Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 12.1.1. |