Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.42% | — | Elementor Website Builder | 14/5/2024 | 17/6/2026 | The Elementor Website Builder – More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in versions up to, and including, 3.21.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 1.5% | 💥 PoC | Elementor Website Builder | 24/4/2024 | 17/6/2026 | Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4. | |
| Modificada | Media (5.4) | 0.46% | — | Elementor Website Builder | 9/4/2024 | 17/6/2026 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Media (5.4) | 0.34% | — | Elementor Website Builder | 27/3/2024 | 17/6/2026 | The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Navigation widget in all versions up to, and including, 3.20.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 4.1% | 💥 Exploit | Elementor Website Builder | 26/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1. | |
| Aplazada | Media (5.9) | 0.34% | — | Visualcomposer Visual Composer Website BuilderAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer.This issue affects Visual Composer Website Builder: from n/a through <= 45.6.0. | |
| Modificada | Media (5.4) | 0.41% | — | Visualcomposer Visual Composer Website Builder | 13/3/2024 | 17/6/2026 | The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 45.6.0 due to insufficient input sanitization and output escaping… | |
| Modificada | Media (5.4) | 0.46% | — | Elementor Website Builder | 29/2/2024 | 17/6/2026 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it… | |
| Modificada | Alta (7.5) | 0.68% | — | Website Builder BY Seedprod | 5/2/2024 | 17/6/2026 | The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprod_lite_new_lpage function in all versions up to, and including, 6.15.21. This makes it… | |
| Modificada | Media (5.4) | 25% | — | Elementor Website Builder | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4. | |
| Modificada | Media (4.3) | 0.32% | — | Website Builder BY Seedprod | 20/10/2023 | 17/6/2026 | The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.15.13.1. This is due to missing or incorrect nonce validation on functionality in the builder.php file. This makes it possible for unauthenticated attackers to change the stripe connect… | |
| Modificada | Media (6.1) | 3.4% | 💥 Exploit | Elementor Website Builder | 14/8/2023 | 17/6/2026 | The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs. | |
| Modificada | Media (4.8) | 0.73% | — | Visualcomposer Visual Composer Website Builder | 7/6/2023 | 17/6/2026 | The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser. | |
| Modificada | Media (5.4) | 0.48% | — | Elementor Website Builder | 7/6/2023 | 17/6/2026 | The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user… | |
| Modificada | Alta (7.2) | 20% | — | Elementor Website Builder | 30/5/2023 | 17/6/2026 | The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role. | |
| Modificada | Media (5.4) | 0.63% | — | Visualcomposer Visual Composer Website Builder | 6/9/2022 | 17/6/2026 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer… | |
| Modificada | Media (5.4) | 0.63% | — | Visualcomposer Visual Composer Website Builder | 6/9/2022 | 17/6/2026 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer… | |
| Modificada | Media (6.1) | 24% | 💥 Exploit | Elementor Website Builder | 13/6/2022 | 17/6/2026 | DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions. | |
| Modificada | Alta (8.8) | 93% | 💥 Exploit | Elementor Website Builder | 19/4/2022 | 17/6/2026 | The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to… | |
| Modificada | Media (6.1) | 25% | 💥 Exploit | Elementor Website Builder | 23/11/2021 | 17/6/2026 | The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue. | |
| Modificada | Media (5.4) | 0.75% | — | Elementor Website Builder | 5/4/2021 | 17/6/2026 | In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’… | |
| Modificada | Media (5.4) | 0.75% | — | Elementor Website Builder | 5/4/2021 | 17/6/2026 | In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’… | |
| Modificada | Media (5.4) | 0.75% | — | Elementor Website Builder | 5/4/2021 | 17/6/2026 | In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified… | |
| Modificada | Media (5.4) | 0.75% | — | Elementor Website Builder | 5/4/2021 | 17/6/2026 | In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’… | |
| Modificada | Media (5.4) | 0.75% | — | Elementor Website Builder | 5/4/2021 | 17/6/2026 | In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’… |