Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
301 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.20% | — | Wpbakery Page BuilderAI | 1/9/2026 | 1/9/2026 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (6.4) | 0.36% | — | Greenshift Animation AND Page Builder BlocksAI | 26/8/2026 | 26/8/2026 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up to, and including, 12.8.9. This is due to insufficient sanitization of API responses before output via innerHTML. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Joomlack Page Builder CKAI | 24/8/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model. | |
| Aplazada | Media (5.3) | 0.44% | — | Joomlack Page Builder CKAI | 24/8/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Joomlack Page Builder CKAI | 17/8/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend. | |
| Aplazada | Media (6.4) | 0.32% | — | Bold-themes Bold Page BuilderAI | 16/8/2026 | 20/8/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, 5.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.39% | — | Kubio AI Page BuilderAI | 16/8/2026 | 20/8/2026 | The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Aplazada | Media (6.3) | 0.42% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input. | |
| Aplazada | Media (6.3) | 0.52% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name. | |
| Aplazada | Crítica (9.2) | 0.51% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system. | |
| Aplazada | Alta (8.7) | 0.50% | — | Joomshaper SP Page BuilderAI | 7/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their… | |
| Aplazada | Media (5.4) | 0.23% | — | Codeless Page BuilderAI | 1/8/2026 | 26/8/2026 | The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged… | |
| Aplazada | Media (6.5) | 0.37% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 30/7/2026 | 30/7/2026 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 28/7/2026 | Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms. | |
| Aplazada | Alta (8.3) | 0.49% | — | JoomlaAIOllyo SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager. | |
| Aplazada | Alta (8.2) | 0.38% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector. | |
| Aplazada | Crítica (9.2) | 0.39% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 12/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector. | |
| Aplazada | Crítica (9.2) | 0.40% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector. | |
| Aplazada | Crítica (9.4) | 0.38% | — | Joomla Page Builder CKAI | 22/7/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE. | |
| Aplazada | Crítica (9.1) | 0.40% | — | Joomlack Page Builder CKAI | 20/7/2026 | 23/7/2026 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views. | |
| Aplazada | Media (6.9) | 0.43% | — | Themexpert Quix Page BuilderAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses. | |
| Aplazada | Alta (8.7) | 0.41% | — | Themexpert Quix Page BuilderAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions. | |
| Aplazada | Media (5.1) | 0.42% | — | Themexpert Quix Page BuilderAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users. | |
| Aplazada | Alta (8.6) | 0.42% | — | Themexpert Quix Page BuilderAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output +… | |
| Aplazada | Alta (8.7) | 0.52% | — | Themexpert Quix Page BuilderAIJoomlaAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files.… |