Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
509 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.35% | — | Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI | 26/8/2026 | 26/8/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.35% | — | Cozythemes Cozy BlocksAI | 25/8/2026 | 26/8/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cozyHoverEffect Block Attribute in all versions up to, and including, 2.2.16 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Alta (7.1) | 0.25% | — | Renzojohnson BlocksAI | 24/8/2026 | 26/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Themegrill Magazine BlocksAI | 24/8/2026 | 24/8/2026 | Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Recipe Card Blocks FOR Gutenberg AND ElementorAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions. | |
| Aplazada | Baja (3.8) | 0.17% | — | Posimyth Nexter BlocksAI | 9/8/2026 | 26/8/2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing. | |
| Aplazada | Media (4.3) | 0.29% | — | Kadence BlocksAI | 6/8/2026 | 12/8/2026 | Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Wpdeveloper Essential BlocksAI | 6/8/2026 | 26/8/2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public. | |
| Aplazada | Alta (7.5) | 1.5% | — | Gutenberg Essential BlocksAI | 6/8/2026 | 26/8/2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product. | |
| Aplazada | Media (6.1) | 0.25% | — | Posimyth Nexter BlocksAI | 6/8/2026 | 29/9/2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to Stored Cross-Site Scripting. | |
| Aplazada | Media (6.4) | 0.33% | — | Kadence BlocksAI | 1/8/2026 | 12/8/2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'toggleIcon' Block Attribute in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.36% | — | Kadence BlocksAI | 1/8/2026 | 12/8/2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content in all versions up to, and including, 3.7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.33% | — | Cozythemes Cozy BlocksAI | 1/8/2026 | 12/8/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping.… | |
| Aplazada | Media (6.4) | 0.42% | — | GenerateblocksAI | 1/8/2026 | 12/8/2026 | The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML Attributes in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (6.4) | 0.43% | — | Cozythemes Cozy BlocksAI | 28/7/2026 | 28/7/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (6.5) | 0.22% | — | Gallery PhotoblocksAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. | |
| Aplazada | Media (5.4) | 0.22% | — | Affiliatexblocks AffiliatexAI | 27/7/2026 | 27/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. | |
| Aplazada | Media (6.4) | 0.43% | — | Cozythemes Cozy BlocksAI | 24/7/2026 | 24/7/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon.view' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (6.4) | 0.43% | — | Cozythemes Cozy BlocksAI | 24/7/2026 | 24/7/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Media (4.3) | 0.86% | — | Posimyth Nexter BlocksAI | 24/7/2026 | 24/7/2026 | The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary… | |
| Aplazada | Media (6.4) | 0.33% | — | Postx Post Grid Gutenberg BlocksAI | 24/7/2026 | 24/7/2026 | The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, and including, 5.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.32% | — | Spectra Gutenberg BlocksAI | 20/7/2026 | 22/7/2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.33% | — | Crocoblock Jetblocks FOR ElementorAI | 13/7/2026 | 13/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0. | |
| Aplazada | Alta (8.8) | 0.42% | — | Tusharimran AblocksAI | 13/7/2026 | 13/7/2026 | Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1. | |
| Aplazada | Media (4.3) | 0.37% | — | Kadencewp Gutenberg Blocks With AIAI | 10/7/2026 | 10/7/2026 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check' function permission callback of the 'process_pattern' REST API… |