Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.58% | — | Webcodingplace Classic Addons Wpbakery Page Builder AddonsAI | 7/1/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Classic Addons – WPBakery Page Builder classic-addons-wpbakery-page-builder-addons allows PHP Local File Inclusion.This issue affects Classic Addons – WPBakery Page Builder: from n/a through <= 3.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Livemesh Addons FOR Wpbakery Page BuilderAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for WPBakery Page Builder addons-for-visual-composer allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through 3.9. | |
| Analizada | Media (5.4) | 0.26% | — | Wpbakery Page Builder | 6/8/2024 | 17/6/2026 | The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, and with… | |
| Aplazada | Media (6.5) | 0.27% | — | Labibahmed Tabs FOR Wpbakery Page BuilderAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in labibahmed Tabs For WPBakery Page Builder allows Stored XSS.This issue affects Tabs For WPBakery Page Builder: from n/a through 1.2. | |
| Modificada | Media (5.4) | 0.29% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 17/7/2024 | 17/6/2026 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_dual_color shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.4) | 0.29% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 17/7/2024 | 17/6/2026 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_banner shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.4) | 0.29% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 17/7/2024 | 17/6/2026 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ult_team shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.29% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 17/7/2024 | 17/6/2026 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_table shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.4) | 0.29% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 17/7/2024 | 17/6/2026 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_pricing shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.30% | — | Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard | 13/6/2024 | 17/6/2026 | The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link attribute within the vc_single_image shortcode in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.51% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows PHP Local File Inclusion.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.14. | |
| Aplazada | Media (6.5) | 0.36% | — | Livemesh Addons FOR Wpbakery Page BuilderAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for WPBakery Page Builder allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through 3.7. | |
| Modificada | Media (5.4) | 0.32% | — | Livemeshthemes Wpbakery Page Builder Addons | 13/3/2024 | 17/6/2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'per_line_mobile' shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (7.2) | 1.5% | — | Unitecms Unlimited Addons FOR Wpbakery Page Builder | 5/2/2024 | 17/6/2026 | The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'importZipFile' function in versions up to, and including, 1.0.42. This makes it possible for authenticated attackers with a role that the administrator previously… | |
| Modificada | Alta (8.8) | 0.22% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 29/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brain Storm Force Ultimate Addons for WPBakery Page Builder.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.17. | |
| Modificada | Media (5.4) | 0.38% | — | Livemeshthemes Wpbakery Page Builder Addons | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh WPBakery Page Builder Addons by Livemesh allows Stored XSS.This issue affects WPBakery Page Builder Addons by Livemesh: from n/a through 3.5. | |
| Modificada | Media (5.4) | 0.31% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 27/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Responsive Tabs FOR Wpbakery Page Builder Project Responsive Tabs FOR Wpbakery Page Builder | 19/6/2023 | 17/6/2026 | The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored… | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Mega Addons FOR Wpbakery Page Builder | 8/5/2023 | 17/6/2026 | The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Ultimate Carousel FOR Wpbakery Page Builder | 8/5/2023 | 17/6/2026 | The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.5) | 0.90% | — | Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder | 17/4/2023 | 17/6/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks | |
| Modificada | Media (5.4) | 0.44% | — | Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder | 17/4/2023 | 17/6/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored… | |
| Modificada | Media (5.4) | 0.47% | — | Image Over Image FOR Wpbakery Page Builder Project Image Over Image FOR Wpbakery Page Builder | 3/4/2023 | 17/6/2026 | The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.38% | — | Webdevocean Image Hover Effects FOR Wpbakery Page Builder | 30/3/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions. | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Wprealize Extensive VC Addons FOR Wpbakery Page Builder | 13/2/2023 | 17/6/2026 | The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE… |