Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.6) | 0.39% | — | Areoi ALL Bootstrap BlocksAI | 18/9/2026 | 18/9/2026 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file… | |
| Aplazada | Media (4.3) | 0.42% | — | Themegrill Magazine BlocksAI | 18/9/2026 | 18/9/2026 | The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.6. This is due to the plugin not properly verifying that a user is authorized to perform an action.… | |
| Aplazada | Media (6.4) | 0.35% | — | Themegrill Magazine BlocksAI | 18/9/2026 | 18/9/2026 | The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6. This is due to insufficient input sanitization and output escaping in the NewsTicker::render() method, which concatenates the clientId block… | |
| Aplazada | Media (6.8) | 0.43% | — | Areoi ALL Bootstrap BlocksAI | 18/9/2026 | 18/9/2026 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed. | |
| Pendiente de análisis | Media (5.3) | 0.45% | — | OmniblocksAI | 17/9/2026 | 23/9/2026 | OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was… | |
| Aplazada | Media (6.5) | 0.22% | — | Motopress Jetblocks FOR ElementorAI | 17/9/2026 | 17/9/2026 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Crocoblock Jetelements FOR ElementorAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | |
| Aplazada | Media (5.3) | 0.34% | — | Prestashop BlockwishlistAI | 16/9/2026 | 22/9/2026 | PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers'… | |
| Aplazada | Crítica (9.8) | 0.52% | — | Crocoblock JetformbuilderAI | 16/9/2026 | 17/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and… | |
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 15/9/2026 | A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 14/9/2026 | A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.57% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 16/9/2026 | A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (6.8) | 0.43% | — | Status301 CoolclockAI | 11/9/2026 | 11/9/2026 | The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed. | |
| Aplazada | Media (6.8) | 0.43% | — | Status301 CoolclockAI | 11/9/2026 | 11/9/2026 | The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed. | |
| Pendiente de análisis | Media (6.9) | 0.44% | — | Ip2location Country BlockerAI | 9/9/2026 | 9/9/2026 | IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers can set the X-Real-IP header to an allowlisted IP address to bypass page, link,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetformbuilderAI | 8/9/2026 | 8/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions. | |
| Aplazada | Media (5.3) | 0.39% | — | Themeisle Otter BlocksAI | 7/9/2026 | 8/9/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the 'watch_checkout' function due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (4.8) | 0.15% | — | Crocoblock JetformbuilderAI | 6/9/2026 | 8/9/2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender.… | |
| Aplazada | Media (6.5) | 0.21% | — | Crocoblock JetformbuilderAI | 6/9/2026 | 8/9/2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Pickplugins ComboblocksAI | 5/9/2026 | 8/9/2026 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress,… | |
| Aplazada | Media (4.7) | 0.17% | — | Crocoblock JetformbuilderAI | 5/9/2026 | 8/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other… | |
| Aplazada | Alta (7.5) | 0.32% | — | Jetformbuilder Dynamic Blocks Form BuilderAI | 5/9/2026 | 8/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft… | |
| Aplazada | Media (5.3) | 0.31% | — | Crocoblock JetpopupAI | 4/9/2026 | 4/9/2026 | Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2. | |
| Aplazada | Media (6.5) | 0.22% | — | Gallery PhotoblocksAI | 2/9/2026 | 3/9/2026 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Creativethemes Blocksy CompanionAI | 1/9/2026 | 1/9/2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and including, 2.1.51 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level… |