Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.22% | — | Wpbakery Page Builder | 6/8/2025 | 17/6/2026 | The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.45% | — | Bricksbuilder BricksAI | 29/7/2025 | 17/6/2026 | The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append… | |
| Analizada | Media (5.4) | 0.17% | — | Elementor Website Builder | 29/7/2025 | 17/6/2026 | The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Analizada | Media (5.4) | 0.27% | — | Wpbakery Page Builder | 24/7/2025 | 17/6/2026 | The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box, Separator With Text, FAQ, Single Image, Custom Header, Button, Call To Action, Progress Bar, Pie Chart, Round Chart, and Line Chart) in all… | |
| Aplazada | Alta (7.6) | 0.31% | — | Funnelkit Funnel BuilderAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder allows SQL Injection.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.10.2. | |
| Aplazada | Alta (7.5) | 0.52% | — | Lambertgroup Html5 Radio Player - Wpbakery Page Builder AddonAI | 16/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Builder Addon lbg-cleverbakery allows Path Traversal.This issue affects HTML5 Radio Player - WPBakery Page Builder Addon: from n/a through <= 2.5. | |
| Aplazada | Media (6.5) | 0.16% | — | Blockswp Theme Builder FOR ElementorAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BlocksWP Theme Builder For Elementor theme-builder-for-elementor allows Cross Site Request Forgery.This issue affects Theme Builder For Elementor: from n/a through <= 1.2.3. | |
| Aplazada | Media (6.5) | 0.23% | — | Bold-themes Bold Page BuilderAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through <= 5.4.1. | |
| Aplazada | Alta (7.2) | 0.51% | — | Crocoblock JetformbuilderAI | 16/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Object Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.1.2. | |
| Aplazada | Media (6.4) | 0.20% | — | Avada Fusion BuilderAI | 16/7/2025 | 17/6/2026 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusion_map' shortcode in all versions up to, and including, 3.12.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Crítica (9.8) | 1.4% | — | Hasthemes Download Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks | 15/7/2025 | 17/6/2026 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation in the handle_files_upload() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated… | |
| Modificada | Crítica (9.8) | 1.1% | — | Hasthemes Download Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks | 15/7/2025 | 17/6/2026 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated… | |
| Modificada | Crítica (9.8) | 1.7% | 💥 PoC | Hasthemes Download Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks | 15/7/2025 | 17/6/2026 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the temp_file_upload() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers… | |
| Aplazada | Crítica (9.3) | 3.6% | 💥 Exploit | BuilderengineAIElfinderAIJquery File UploadAI | 10/7/2025 | 17/6/2026 | An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to properly validate or restrict file types or locations during upload operations, allowing an attacker to upload a malicious .php… | |
| Aplazada | Crítica (9.2) | 0.33% | — | Builder.io Qwik-cityAI | 9/7/2025 | 17/6/2026 | @builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the file containing the symbol. When an invalid qfunc is sent, the server does not handle the thrown error. The error then causes Node JS to exit. This vulnerability is fixed in 1.13.0. | |
| Aplazada | Media (4.3) | 0.22% | — | Zoomit Woocommerce Shop Page BuilderAI | 4/7/2025 | 17/6/2026 | Missing Authorization vulnerability in ZoomIt WooCommerce Shop Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce Shop Page Builder: from n/a through 2.27.7. | |
| Aplazada | Media (6.5) | 0.20% | — | Abditsori My-resume-builderAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in abditsori My Resume Builder my-resume-builder allows Stored XSS.This issue affects My Resume Builder: from n/a through <= 1.0.3. | |
| Aplazada | Media (4.3) | 0.16% | — | Edgarrojas Woo-pdf-invoice-builderAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Cross Site Request Forgery.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 1.2.148. | |
| Aplazada | Media (6.4) | 0.19% | — | Boldgrid Post AND Page BuilderAI | 20/6/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Server Side Request Forgery.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.8. | |
| Aplazada | Media (4.3) | 0.14% | — | Boldgrid Post AND Page BuilderAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Cross Site Request Forgery.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.8. | |
| Aplazada | Media (5.3) | 0.31% | — | Appcheap APP BuilderAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in App Cheap App Builder app-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects App Builder: from n/a through <= 5.5.6. | |
| Analizada | Alta (7.2) | 0.61% | — | Fastlinemedia Beaver Builder | 20/6/2025 | 17/6/2026 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_enabled_icons' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above,… | |
| Analizada | Media (5.4) | 0.19% | — | Wpbakery Page Builder | 19/6/2025 | 17/6/2026 | The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Builder feature in all versions up to, and including, 8.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.26% | — | Wpquark Eform - Wordpress Form BuilderAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPQuark eForm - WordPress Form Builder wp-fsqm-pro allows Reflected XSS.This issue affects eForm - WordPress Form Builder: from n/a through < 4.19.1. | |
| Analizada | Media (5.4) | 0.19% | — | Elementor Page Builder | 10/6/2025 | 17/6/2026 | The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text’ parameter in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… |