Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.18% | — | Justintadlock Widgets Reset | 15/5/2025 | 17/6/2026 | The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (6.8) | 0.55% | — | Wpengine Genesis Blocks | 15/5/2025 | 17/6/2026 | The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks. | |
| Analizada | Media (6.1) | 0.57% | 💥 Exploit | Codeflock WP Desklite | 15/5/2025 | 17/6/2026 | The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (4.8) | 0.31% | — | Reputeinfosystems Social Share AND Social Locker | 15/5/2025 | 17/6/2026 | The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (6.5) | 0.30% | — | Flickdevs Countdown Timer FOR Wordpress Block Editor | 15/5/2025 | 17/6/2026 | The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Crítica (9.8) | 7.4% | 💥 Exploit | Frontend Login AND Registration BlocksAI | 9/5/2025 | 17/6/2026 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email via the… | |
| Aplazada | Media (6.5) | 0.26% | — | Tusharimran AblocksAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC aBlocks ablocks allows Stored XSS.This issue affects aBlocks: from n/a through <= 1.9.2. | |
| Aplazada | Media (5.9) | 0.27% | — | Aweos Gmbh Aweos WP LockAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AWEOS GmbH AWEOS WP Lock aweos-wp-lock allows Stored XSS.This issue affects AWEOS WP Lock: from n/a through <= 1.4.8. | |
| Aplazada | Media (5.9) | 0.27% | — | Wpplugin Time ClockAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Time Clock time-clock allows Stored XSS.This issue affects Time Clock: from n/a through <= 1.2.3. | |
| Aplazada | Media (6.5) | 0.26% | — | BlockspareAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blockspare Blockspare blockspare allows Stored XSS.This issue affects Blockspare: from n/a through <= 3.2.9. | |
| Aplazada | Media (6.5) | 0.30% | — | Dotcamp Ultimate BlocksAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks ultimate-blocks allows DOM-Based XSS.This issue affects Ultimate Blocks: from n/a through <= 3.2.9. | |
| Aplazada | Media (5.3) | 0.36% | — | Cozythemes Cozy BlocksAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through <= 2.1.22. | |
| Aplazada | Media (6.4) | 0.26% | — | Oliver Campion Display Remote Posts BlockAI | 7/5/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Oliver Campion Display Remote Posts Block display-remote-posts-block allows Server Side Request Forgery.This issue affects Display Remote Posts Block: from n/a through <= 1.1.0. | |
| Aplazada | Media (4.9) | 0.40% | — | Creativethemes BlocksyAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in creativethemeshq Blocksy blocksy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blocksy: from n/a through <= 2.0.97. | |
| Aplazada | Media (5.4) | 0.33% | — | Login LockdownAI | 7/5/2025 | 17/6/2026 | The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_tool function in all versions up to, and including, 2.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain a valid nonce… | |
| Aplazada | Media (6.4) | 0.31% | — | Cision BlockAI | 6/5/2025 | 17/6/2026 | The Cision Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Baja (2.3) | 0.79% | — | Ublockorigin Ublock OriginDebian Linux | 2/5/2025 | 17/6/2026 | A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file src/js/1p-filters.js of the component UI. The manipulation leads to inefficient regular expression complexity. It is possible to launch the attack… | |
| Aplazada | Media (4.3) | 0.15% | — | Codebangers ALL IN ONE Time Clock LiteAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Codebangers All in One Time Clock Lite aio-time-clock-lite allows Cross Site Request Forgery.This issue affects All in One Time Clock Lite: from n/a through < 1.3.326. | |
| Aplazada | Alta (7.1) | 0.15% | — | Ahsanullah Akanda WP Custom CMS BlockAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ahsanullah Akanda Wp Custom CMS Block wp-custom-cms-block allows Stored XSS.This issue affects Wp Custom CMS Block: from n/a through <= 2.1. | |
| Aplazada | Alta (8.8) | 0.44% | — | Frontend Login AND Registration BlocksAI | 24/4/2025 | 17/6/2026 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.8. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.32% | — | Advanced Accordion Gutenberg BlockAI | 24/4/2025 | 17/6/2026 | The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above,… | |
| Analizada | Media (6.1) | 0.24% | — | Four Kitchens Block Class | 23/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class allows Cross-Site Scripting (XSS).This issue affects Block Class: from 4.0.0 before 4.0.1. | |
| Modificada | Media (5.4) | 0.22% | — | Sktthemes SKT Blocks | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a through <= 2.0. | |
| Analizada | Alta (8.8) | 2.5% | 💥 PoC | Greenshiftwp Greenshift - Animation AND Page Builder Blocks | 22/4/2025 | 17/6/2026 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb_make_proxy_api_request() function in versions 11.4 to 11.4.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (6.4) | 0.32% | — | SB Chart BlockAI | 19/4/2025 | 17/6/2026 | The SB Chart block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… |