Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.34% | — | Webdevocean Team BuilderAI | 9/6/2025 | 17/6/2026 | Missing Authorization vulnerability in looks_awesome Team Builder a-team-showcase allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Builder: from n/a through <= 1.5.7. | |
| Aplazada | Media (6.5) | 0.25% | — | Wpsoul Greenshift Animation AND Page Builder BlocksAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows DOM-Based XSS.This issue affects Greenshift: from n/a through <= 11.5.5. | |
| Aplazada | Media (4.3) | 0.31% | — | Cozmoslabs Profile BuilderAI | 6/6/2025 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder profile-builder allows Phishing.This issue affects Profile Builder: from n/a through <= 3.13.8. | |
| Aplazada | Media (4.3) | 0.16% | — | Wptablebuilder WP Table BuilderAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Table Builder WP Table Builder wp-table-builder allows Cross Site Request Forgery.This issue affects WP Table Builder: from n/a through <= 2.0.6. | |
| Aplazada | Media (6.5) | 0.25% | — | Stiofan Blockstrap Page Builder BlocksAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stiofan BlockStrap Page Builder - Bootstrap Blocks blockstrap-page-builder-blocks allows Stored XSS.This issue affects BlockStrap Page Builder - Bootstrap Blocks: from n/a through <= 0.1.36. | |
| Aplazada | Media (5.3) | 0.34% | — | TaskbuilderAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in taskbuilder Taskbuilder taskbuilder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Taskbuilder: from n/a through <= 4.0.7. | |
| Aplazada | Media (6.5) | 0.20% | — | Posimyth THE Plus Addons FOR Elementor Page BuilderAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 6.2.7. | |
| Aplazada | Media (6.4) | 0.22% | — | BM Content BuilderAI | 6/6/2025 | 17/6/2026 | The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'ux_cb_page_options_save' function in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject… | |
| Aplazada | Media (6.4) | 0.29% | — | Cozmoslabs Profile BuilderAI | 3/6/2025 | 17/6/2026 | The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.43% | — | Offsprout Page BuilderAI | 31/5/2025 | 17/6/2026 | The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization placed on the permission_callback() function in versions 2.2.1 to 2.15.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to read, create, update or delete… | |
| Aplazada | Crítica (9.8) | 0.46% | — | Thimpress Course BuilderAI | 29/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThimPress Course Builder course-builder allows Object Injection.This issue affects Course Builder: from n/a through < 3.6.6. | |
| Aplazada | Media (6.4) | 0.40% | — | Bold-themes Bold Page BuilderAI | 29/5/2025 | 17/6/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ parameter in all versions up to, and including, 5.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Alta (7.1) | 0.25% | — | Dastan800 Visual BuilderAI | 23/5/2025 | 17/6/2026 | Missing Authorization vulnerability in dastan800 Visual Builder visual-builder allows Reflected XSS.This issue affects Visual Builder: from n/a through <= 1.2.2. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Kamleshyadav Pixel Wordpress Form Builder Plugin & AutoresponderAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder allows Blind SQL Injection.This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through <= 1.0.2. | |
| Aplazada | Media (6.5) | 0.29% | — | Chopluggins Custom PC Builder Lite FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ChoPlugins.com Custom PC Builder Lite for WooCommerce custom-pc-builder-lite-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.5) | 0.35% | — | Crocoblock JET WOO BuilderAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Crocoblock JetWooBuilder jet-woo-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetWooBuilder: from n/a through <= 2.1.18. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Themegusta Smart Sections Theme Builder - Wpbakery Page Builder AddonAI | 19/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themegusta Smart Sections Theme Builder - WPBakery Page Builder Addon.This issue affects Smart Sections Theme Builder - WPBakery Page Builder Addon: from n/a through 1.7.8. | |
| Aplazada | Media (5.9) | 0.21% | — | Stylemixthemes Cost Calculator BuilderAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder allows Stored XSS.This issue affects Cost Calculator Builder: from n/a through <= 3.2.74. | |
| Aplazada | Media (6.5) | 0.25% | — | Visualcomposer Visual Composer Website BuilderAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through <= 45.11.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Xpro Addons FOR Beaver BuilderAIFastlinemedia Beaver BuilderAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Addons For Beaver Builder – Lite xpro-addons-beaver-builder-elementor allows Stored XSS.This issue affects Xpro Addons For Beaver Builder – Lite: from n/a through <= 1.5.5. | |
| Aplazada | Media (6.4) | 0.29% | — | Bold-themes Bold Page BuilderAI | 18/5/2025 | 17/6/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (4.3) | 0.16% | — | Loopus WP Ultimate Tours BuilderAI | 16/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Ultimate Tours Builder WP_UltimateToursBuilder allows Cross Site Request Forgery.This issue affects WP Ultimate Tours Builder: from n/a through <= 1.055. | |
| Aplazada | Media (5.4) | 0.15% | — | Kamleshyadav Pixel Wordpress Form Builder Plugin AND AutoresponderAI | 16/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder allows Cross Site Request Forgery.This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through <= 1.0.3. | |
| Analizada | Media (6.1) | 0.22% | — | Dpgaspar Flask-appbuilder | 16/5/2025 | 17/6/2026 | Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. Flask-AppBuilder 4.6.2 introduced the `FAB_SAFE_REDIRECT_HOSTS` configuration variable,… | |
| Analizada | Media (6.1) | 0.26% | — | Funnelkit Funnel Builder | 15/5/2025 | 17/6/2026 | The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks |