Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

1033 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.42%—Themegrill Magazine BlocksAI18/9/202618/9/2026
The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.6. This is due to the plugin not properly verifying that a user is authorized to perform an action.…
AplazadaMedia (6.4)0.35%—Themegrill Magazine BlocksAI18/9/202618/9/2026
The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6. This is due to insufficient input sanitization and output escaping in the NewsTicker::render() method, which concatenates the clientId block…
AplazadaMedia (6.8)0.43%—Areoi ALL Bootstrap BlocksAI18/9/202618/9/2026
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
Pendiente de análisisMedia (5.3)0.45%—OmniblocksAI17/9/202623/9/2026
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was…
AplazadaMedia (6.5)0.22%—Motopress Jetblocks FOR ElementorAI17/9/202617/9/2026
Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
AplazadaMedia (6.5)0.22%—Crocoblock Jetelements FOR ElementorAI17/9/202619/9/2026
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.
AplazadaMedia (5.3)0.34%—Prestashop BlockwishlistAI16/9/202622/9/2026
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers'…
AplazadaCrítica (9.8)0.52%—Crocoblock JetformbuilderAI16/9/202617/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and…
Pendiente de análisisMedia (6.9)0.44%—Ip2location Country BlockerAI9/9/20269/9/2026
IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers can set the X-Real-IP header to an allowlisted IP address to bypass page, link,…
AplazadaAlta (7.1)0.25%—Crocoblock JetformbuilderAI8/9/20268/9/2026
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.
AplazadaMedia (5.3)0.39%—Themeisle Otter BlocksAI7/9/20268/9/2026
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the 'watch_checkout' function due to missing validation on a user controlled key. This makes it possible for…
AplazadaMedia (4.8)0.15%—Crocoblock JetformbuilderAI6/9/20268/9/2026
The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender.…
AplazadaMedia (6.5)0.21%—Crocoblock JetformbuilderAI6/9/20268/9/2026
The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion…
AplazadaCrítica (9.8)0.45%—Pickplugins ComboblocksAI5/9/20268/9/2026
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress,…
AplazadaMedia (4.7)0.17%—Crocoblock JetformbuilderAI5/9/20268/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other…
AplazadaAlta (7.5)0.32%—Jetformbuilder Dynamic Blocks Form BuilderAI5/9/20268/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft…
AplazadaMedia (5.3)0.31%—Crocoblock JetpopupAI4/9/20264/9/2026
Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2.
AplazadaMedia (6.5)0.22%—Gallery PhotoblocksAI2/9/20263/9/2026
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
AplazadaMedia (6.4)0.33%—Creativethemes Blocksy CompanionAI1/9/20261/9/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and including, 2.1.51 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level…
AplazadaMedia (5.3)0.39%—Cozythemes Cozy BlocksAI1/9/20261/9/2026
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaAlta (7.1)0.60%—Powsybl Power System BlocksAI28/8/20269/9/2026
PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and environment variables into strings interpreted through bash -c or cmd /c without sufficient escaping. Attacker-controlled…
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI28/8/202628/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
AplazadaCrítica (9.8)2.9%—23blocks-os Ai-maestroAI28/8/20269/9/2026
An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.
AplazadaMedia (6.4)0.36%—Greenshift Animation AND Page Builder BlocksAI26/8/202626/8/2026
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up to, and including, 12.8.9. This is due to insufficient sanitization of API responses before output via innerHTML. This makes it possible for authenticated…
AplazadaMedia (6.4)0.35%—Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI26/8/202626/8/2026
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…