Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.40% | — | Ideabox Powerpack Addons FOR Elementor | 13/6/2024 | 17/6/2026 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Link Effects widget in all versions up to, and including, 2.7.20 due to insufficient input sanitization and output escaping. This… | |
| Modificada | Alta (8.8) | 0.43% | — | Ideabox Powerpack Addons FOR Elementor | 8/6/2024 | 17/6/2026 | The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.32% | — | Ideabox Powerpack Addons FOR Elementor | 30/5/2024 | 17/6/2026 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘pp_animated_gradient_bg_color’ parameter in all versions up to, and including, 2.7.19 due to insufficient input sanitization and output escaping. This makes… | |
| Analizada | Media (4.3) | 0.51% | — | Metabox Meta BOX | 15/4/2024 | 17/6/2026 | The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts. | |
| Modificada | Media (5.4) | 0.36% | — | Ideabox Powerpack Addons FOR Elementor | 9/4/2024 | 17/6/2026 | The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Tweet widget in all versions up to, and including, 2.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Modificada | Media (5.4) | 0.34% | — | Ideabox Powerpack FOR Beaver Builder | 9/4/2024 | 17/6/2026 | The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in multiple elements in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.43% | — | Metabox Custom Post Types Custom Fields MoreAI | 9/4/2024 | 17/6/2026 | The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and custom post meta in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping on user supplied post meta values. This makes it possible… | |
| Modificada | Media (5.4) | 0.34% | — | Ideabox Powerpack Addons FOR Elementor | 30/3/2024 | 17/6/2026 | The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the *_html_tag* attribute of multiple widgets in all versions up to, and including, 2.7.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.42% | — | Ideabox Powerpack Addons FOR Elementor | 29/2/2024 | 17/6/2026 | The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings of the Twitter Buttons Widget in all versions up to, and including, 2.7.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.42% | — | Ideabox Powerpack Addons FOR Elementor | 7/2/2024 | 17/6/2026 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's buttons in all versions up to, and including, 2.7.14 due to insufficient input sanitization and output escaping on user supplied URL values. This makes it… | |
| Modificada | Media (5.4) | 0.41% | — | Metabox Meta BOX | 5/2/2024 | 17/6/2026 | The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta values displayed through the plugin's shortcode in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Media (4.3) | 0.20% | — | Ideabox Powerpack Addons FOR Elementor | 3/1/2024 | 17/6/2026 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13. This is due to missing or incorrect nonce validation in the powerpack-lite-for-elementor/classes/class-pp-admin-settings.php file.… | |
| Modificada | Media (6.1) | 0.42% | — | Ideabox Powerpack Addons FOR Elementor | 14/12/2023 | 17/6/2026 | Vulnerability in IdeaBox Creations PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a through 2.9.23. | |
| Modificada | Alta (8.8) | 0.28% | — | Underdock Open Graph Metabox | 25/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Niels van Renselaar Open Graph Metabox plugin <= 1.4.4 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | WP Gallery Metabox Project WP Gallery Metabox | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hardik Kalathiya WP Gallery Metabox plugin <= 1.0.0 versions. | |
| Modificada | Media (4.3) | 0.46% | — | Gallery-metabox Project Gallery-metabox | 12/7/2023 | 17/6/2026 | The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to obtain a list of images attached to a post. | |
| Modificada | Media (4.3) | 0.41% | — | Gallery-metabox Project Gallery-metabox | 12/7/2023 | 17/6/2026 | The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin. | |
| Modificada | Media (6.1) | 0.38% | — | IP Metaboxes Project IP Metaboxes | 12/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Phan Chuong IP Metaboxes plugin <= 2.1.1. | |
| Modificada | Media (4.8) | 0.37% | — | IP Metaboxes Project IP Metaboxes | 12/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Phan Chuong IP Metaboxes plugin <= 2.1.1 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Gallery Metabox Project Gallery Metabox | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bill Erickson Gallery Metabox plugin <= 1.5 versions. | |
| Modificada | Crítica (9) | 0.44% | — | Profelis Sambabox | 30/3/2022 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause execute arbitrary codes on the vulnerable server. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior… | |
| Modificada | Media (6.7) | 0.33% | — | Profelis Sambabox | 30/3/2022 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause run arbitrary code. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86. | |
| Modificada | Media (6.1) | 0.67% | — | Archivistabox | 16/3/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in ArchivistaBox webclient allows an attacker to craft a malicious link, executing JavaScript in the context of a victim's browser. This issue affects all ArchivistaBox versions prior to 2022/I. | |
| Modificada | Media (6.1) | 0.88% | — | Ideabox Powerpack FOR Beaver Builder | 14/2/2022 | 17/6/2026 | The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.88% | — | Ideabox Powerpack Addons FOR Elementor | 3/1/2022 | 17/6/2026 | The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue |