Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

49 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.80%—Cozmoslabs Profile Builder31/7/202417/6/2026
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.
AnalizadaCrítica (9.1)29%💥 ExploitCozmoslabs Profile Builder29/7/202417/6/2026
The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.
AplazadaMedia (5.3)0.22%—Cozmoslabs Profile BuilderAI17/5/202417/6/2026
Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.
ModificadaAlta (7.5)2.4%💥 PoCCozmoslabs Profile Builder5/2/202417/6/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all versions up to, and including, 3.10.8. This…
ModificadaAlta (8.8)0.26%—Cozmoslabs Profile Builder31/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.
ModificadaAlta (7.5)0.49%—Cozmoslabs Profile Builder24/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.
ModificadaMedia (6.1)0.33%—Cozmoslabs Profile Builder13/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Profile Builder Pro allows Reflected XSS.This issue affects Profile Builder Pro: from n/a through 3.10.0.
ModificadaMedia (4.3)0.35%—Cozmoslabs Profile Builder11/1/202417/6/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler function in all versions up to, and including, 3.10.7. This makes it possible for…
ModificadaAlta (8.8)0.25%—Cozmoslabs Profile Builder13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin <= 3.10.3 versions.
ModificadaMedia (4.3)0.23%—Cozmoslabs Profile Builder4/9/202317/6/2026
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog
ModificadaAlta (8.1)0.99%—Cozmoslabs Profile Builder27/4/202317/6/2026
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function…
ModificadaMedia (6.5)0.77%—Cozmoslabs Profile Builder14/2/202317/6/2026
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This…
ModificadaMedia (4.3)0.27%—Cozmoslabs Profile Builder11/10/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on.
ModificadaMedia (6.5)2.3%—User-meta User Meta User Profile Builder AND User Management8/6/202217/6/2026
The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads
ModificadaMedia (4.8)0.59%—User-meta User Meta User Profile Builder AND User Management30/5/202217/6/2026
The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (4.8)0.65%—Cozmoslabs Profile Builder4/4/202217/6/2026
The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (6.1)2.7%💥 ExploitCozmoslabs Profile Builder24/2/202217/6/2026
The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes…
ModificadaCrítica (9.8)7.6%💥 ExploitCozmoslabs Profile Builder16/8/202117/6/2026
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for…
ModificadaMedia (4.8)0.61%—Cozmoslabs Profile Builder2/8/202117/6/2026
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored…
ModificadaAlta (7.5)1.3%—Cozmoslabs Profile Builder22/8/201917/6/2026
The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.
ModificadaMedia (6.1)0.91%—Cozmoslabs Profile Builder21/8/201917/6/2026
The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)0.91%—Cozmoslabs Profile Builder21/8/201917/6/2026
The profile-builder plugin before 2.2.5 for WordPress has XSS.
ModificadaMedia (6.1)0.91%—Cozmoslabs Profile Builder21/8/201917/6/2026
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
ModificadaMedia (6.1)1.2%—Cozmoslabs Profile Builder6/10/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.
Orbitaley — Vulnerabilidades