Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
509 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.36% | — | Wpdownloadmanager Gutenberg Blocks FOR Wordpress Download Manager | 3/5/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions. | |
| Modificada | Media (4.3) | 0.55% | — | Creativethemes Blocksy Companion | 2/5/2023 | 17/6/2026 | The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example | |
| Modificada | Media (5.4) | 0.34% | — | Creativethemes Blocksy Companion | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions. | |
| Modificada | Media (4.3) | 0.28% | — | Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks | 27/3/2023 | 17/6/2026 | The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Alta (8.1) | 0.73% | — | Simplygallery Simply Gallery Blocks With Lightbox | 27/3/2023 | 17/6/2026 | The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a… | |
| Modificada | Crítica (9.8) | 4.8% | 💥 Exploit | Blocksera Cryptocurrency Widgets Pack | 2/1/2023 | 17/6/2026 | The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Crítica (9.8) | 2.3% | 💥 Exploit | Blocksera Cryptocurrency Widgets Pack | 15/12/2022 | 17/6/2026 | Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress. | |
| Modificada | Media (5.4) | 0.60% | — | Wpchill Gallery Photoblocks | 9/9/2022 | 17/6/2026 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress. | |
| Modificada | Alta (8.8) | 0.37% | — | Wpchill Gallery Photoblocks | 23/8/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress. | |
| Modificada | Alta (8.8) | 0.56% | — | Global Content Blocks Project Global Content Blocks | 23/6/2022 | 17/6/2026 | A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. | |
| Modificada | Media (4.8) | 5.7% | 💥 Exploit | Dwbooster CP Blocks | 7/3/2022 | 17/6/2026 | The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | |
| Modificada | Crítica (9.8) | 6.7% | 💥 Exploit | Blocksera Image Hover Effects | 15/12/2021 | 17/6/2026 | Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin. | |
| Modificada | Media (5.4) | 0.62% | — | Generateblocks | 29/11/2021 | 17/6/2026 | The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks. | |
| Modificada | Media (5.3) | 1.3% | — | Find MY Blocks Project Find MY Blocks | 18/10/2021 | 17/6/2026 | The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enumerate private posts' titles. | |
| Modificada | Media (4.3) | 0.76% | — | Wpxpo Postx - Gutenberg Blocks FOR Post Grid | 27/9/2021 | 17/6/2026 | The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID. | |
| Modificada | Media (5.4) | 0.53% | — | Wpxpo Postx - Gutenberg Blocks FOR Post Grid | 27/9/2021 | 17/6/2026 | The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode. | |
| Modificada | Media (5.4) | 0.55% | — | Wpxpo Postx - Gutenberg Blocks FOR Post Grid | 27/9/2021 | 17/6/2026 | The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block. | |
| Modificada | Media (6.5) | 0.72% | — | Wpxpo Postx - Gutenberg Blocks FOR Post Grid | 27/9/2021 | 17/6/2026 | The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values. | |
| Modificada | Media (5.4) | 0.62% | — | Wpzoom Recipe Card Blocks FOR Gutenberg & Elementor | 27/9/2021 | 17/6/2026 | The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site… | |
| Modificada | Media (6.1) | 0.83% | — | Wpzoom Recipe Card Blocks FOR Gutenberg & Elementor | 27/9/2021 | 17/6/2026 | The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.4) | 0.62% | — | Simplygallery Simply Gallery Blocks With Lightbox | 30/8/2021 | 17/6/2026 | A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.0 & below). The vulnerability exists in the Lightbox functionality where a user with low privileges is allowed to execute arbitrary script code within the context of the application. This… | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Automattic Woocommerce Blocks | 26/7/2021 | 17/6/2026 | woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the… | |
| Modificada | Media (5.4) | 0.59% | — | Blocksera Image Hover Effects | 5/5/2021 | 17/6/2026 | The “Image Hover Effects – Elementor Addon” WordPress Plugin before 1.3.4 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Media (5.4) | 0.59% | — | Brainstormforce Elementor - Header, Footer & Blocks Template | 5/5/2021 | 17/6/2026 | The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Media (5.5) | 2.0% | — | Codeblocks Code\ | 8/4/2020 | 17/6/2026 | A buffer overflow vulnerability in Code::Blocks 17.12 allows an attacker to execute arbitrary code via a crafted project file. |