Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

54 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.58%—Webcodingplace Classic Addons Wpbakery Page Builder AddonsAI7/1/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Classic Addons – WPBakery Page Builder classic-addons-wpbakery-page-builder-addons allows PHP Local File Inclusion.This issue affects Classic Addons – WPBakery Page Builder: from n/a through <= 3.0.
AplazadaMedia (6.5)0.26%—Livemesh Addons FOR Wpbakery Page BuilderAI18/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for WPBakery Page Builder addons-for-visual-composer allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through 3.9.
AnalizadaMedia (5.4)0.26%—Wpbakery Page Builder6/8/202417/6/2026
The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, and with…
AplazadaMedia (6.5)0.27%—Labibahmed Tabs FOR Wpbakery Page BuilderAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in labibahmed Tabs For WPBakery Page Builder allows Stored XSS.This issue affects Tabs For WPBakery Page Builder: from n/a through 1.2.
ModificadaMedia (5.4)0.29%—Brainstormforce Ultimate Addons FOR Wpbakery Page Builder17/7/202417/6/2026
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_dual_color shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaMedia (5.4)0.29%—Brainstormforce Ultimate Addons FOR Wpbakery Page Builder17/7/202417/6/2026
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_banner shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaMedia (5.4)0.29%—Brainstormforce Ultimate Addons FOR Wpbakery Page Builder17/7/202417/6/2026
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ult_team shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
ModificadaMedia (5.4)0.29%—Brainstormforce Ultimate Addons FOR Wpbakery Page Builder17/7/202417/6/2026
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_table shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaMedia (5.4)0.29%—Brainstormforce Ultimate Addons FOR Wpbakery Page Builder17/7/202417/6/2026
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_pricing shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
ModificadaMedia (5.4)0.30%—Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard13/6/202417/6/2026
The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link attribute within the vc_single_image shortcode in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaAlta (7.1)0.51%—Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI17/5/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows PHP Local File Inclusion.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.14.
AplazadaMedia (6.5)0.36%—Livemesh Addons FOR Wpbakery Page BuilderAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for WPBakery Page Builder allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through 3.7.
ModificadaMedia (5.4)0.32%—Livemeshthemes Wpbakery Page Builder Addons13/3/202417/6/2026
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'per_line_mobile' shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaAlta (7.2)1.5%—Unitecms Unlimited Addons FOR Wpbakery Page Builder5/2/202417/6/2026
The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'importZipFile' function in versions up to, and including, 1.0.42. This makes it possible for authenticated attackers with a role that the administrator previously…
ModificadaAlta (8.8)0.22%—Brainstormforce Ultimate Addons FOR Wpbakery Page Builder29/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Brain Storm Force Ultimate Addons for WPBakery Page Builder.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.17.
ModificadaMedia (5.4)0.38%—Livemeshthemes Wpbakery Page Builder Addons14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh WPBakery Page Builder Addons by Livemesh allows Stored XSS.This issue affects WPBakery Page Builder Addons by Livemesh: from n/a through 3.5.
ModificadaMedia (5.4)0.31%—Brainstormforce Ultimate Addons FOR Wpbakery Page Builder27/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 versions.
ModificadaMedia (5.4)0.44%—Responsive Tabs FOR Wpbakery Page Builder Project Responsive Tabs FOR Wpbakery Page Builder19/6/202317/6/2026
The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored…
ModificadaMedia (5.4)0.44%—Topdigitaltrends Mega Addons FOR Wpbakery Page Builder8/5/202317/6/2026
The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.44%—Topdigitaltrends Ultimate Carousel FOR Wpbakery Page Builder8/5/202317/6/2026
The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (6.5)0.90%—Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder17/4/202317/6/2026
The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
ModificadaMedia (5.4)0.44%—Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder17/4/202317/6/2026
The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored…
ModificadaMedia (5.4)0.47%—Image Over Image FOR Wpbakery Page Builder Project Image Over Image FOR Wpbakery Page Builder3/4/202317/6/2026
The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.38%—Webdevocean Image Hover Effects FOR Wpbakery Page Builder30/3/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions.
ModificadaAlta (7.5)55%💥 ExploitWprealize Extensive VC Addons FOR Wpbakery Page Builder13/2/202317/6/2026
The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE…
Orbitaley — Vulnerabilidades