Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
984 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.47% | — | Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates) | 9/7/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.51% | — | Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates) | 9/7/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.50% | — | Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates) | 9/7/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Modificada | Media (5.4) | 0.24% | — | Codeastrology Ultraaddons | 6/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam UltraAddons Elementor Lite ultraaddons-elementor-lite allows DOM-Based XSS.This issue affects UltraAddons Elementor Lite: from n/a through <= 2.0.2. | |
| Analizada | Media (6.5) | 0.52% | — | Livemesh Elementor Addons | 6/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons for Elementor.This issue affects Livemesh Addons for Elementor: from n/a through 8.4.0. | |
| Modificada | Media (4.3) | 0.58% | — | Leap13 Premium Addons FOR Elementor | 4/7/2024 | 17/6/2026 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. This is due to processing user-supplied input as a regular expression. This makes it possible for authenticated attackers, with Author-level access and… | |
| Modificada | Media (5.4) | 0.34% | — | Livemeshelementor Addons FOR Elementor | 4/7/2024 | 17/6/2026 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Posts Grid widget in all versions up to, and including, 8.3.7 due to insufficient input sanitization and output escaping on user supplied attributes like 'grid_skin'. This makes it possible for… | |
| Modificada | Media (5.4) | 0.34% | — | Livemeshelementor Addons FOR Elementor | 4/7/2024 | 17/6/2026 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Marquee Text Widget, Testimonials Widget, and Testimonial Slider widgets in all versions up to, and including, 8.4.1 due to insufficient input sanitization and output escaping on user supplied… | |
| Modificada | Media (5.4) | 0.43% | — | Livemeshelementor Addons FOR Elementor | 4/7/2024 | 17/6/2026 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 8.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.89% | — | Livemeshelementor Addons FOR Elementor | 4/7/2024 | 17/6/2026 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.4 via several of the plugin's widgets through the 'style' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute… | |
| Modificada | Media (5.4) | 0.36% | — | Leap13 Premium Addons FOR Elementor | 3/7/2024 | 17/6/2026 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 4.10.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Media (5.4) | 0.40% | — | Posimyth THE Plus Addons FOR Elementor | 3/7/2024 | 17/6/2026 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied… | |
| Modificada | Media (5.4) | 0.33% | — | Wedevs Happy Addons FOR Elementor | 29/6/2024 | 17/6/2026 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.36% | — | Posimyth THE Plus Addons FOR Elementor | 27/6/2024 | 17/6/2026 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘video_color’ parameter in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it… | |
| Modificada | Media (5.4) | 0.26% | — | Exclusiveaddons Exclusive Addons FOR Elementor | 26/6/2024 | 17/6/2026 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Card widget in all versions up to, and including, 2.6.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Crítica (9.8) | 0.41% | — | Buy-addons Complete FOR Create A Quote IN Frontend Backend PROAI | 24/6/2024 | 17/6/2026 | SQL injection vulnerability in the module "Complete for Create a Quote in Frontend + Backend Pro" (askforaquotemodul) <= 1.0.51 from Buy Addons for PrestaShop allows attackers to view sensitive information and cause other impacts via methods `AskforaquotemodulcustomernewquoteModuleFrontController::run()`,… | |
| Modificada | Media (5.4) | 0.32% | — | Fusionplugin Table Addons FOR Elementor | 22/6/2024 | 17/6/2026 | The Table Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Modificada | Alta (8.8) | 0.62% | — | Posimyth THE Plus Addons FOR Elementor | 21/6/2024 | 17/6/2026 | The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.5.4 via the 'magazine_style' parameter within the Dynamic Smart Showcase widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Media (6.1) | 0.31% | — | Posimyth THE Plus Addons FOR Elementor | 21/6/2024 | 17/6/2026 | The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘forgoturl’ attribute within the plugin's WP Login & Register widget in all versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Modificada | Media (5.4) | 0.35% | — | Wpzoom Addons FOR Elementor | 20/6/2024 | 17/6/2026 | The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Team Members widget in all versions up to, and including, 1.1.38 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.3) | 0.29% | — | Buy-addons BagoogleshoppingAI | 19/6/2024 | 17/6/2026 | In the module "Bulk Export products to Google Merchant-Google Shopping" (bagoogleshopping) up to version 1.0.26 from Buy Addons for PrestaShop, a guest can perform SQL injection via`GenerateCategories::renderCategories(). | |
| Analizada | Alta (8.8) | 0.63% | — | Leap13 Premium Addons | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Premium Addons Premium Addons PRO.This issue affects Premium Addons PRO: from n/a through 2.9.0. | |
| Analizada | Media (4.3) | 0.36% | — | Wpmet Elements KIT Elementor Addons | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Wpmet Elements kit Elementor addons.This issue affects Elements kit Elementor addons: from n/a through 2.9.0. | |
| Modificada | Media (5.4) | 0.40% | — | Ideabox Powerpack Addons FOR Elementor | 13/6/2024 | 17/6/2026 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Link Effects widget in all versions up to, and including, 2.7.20 due to insufficient input sanitization and output escaping. This… | |
| Modificada | Media (5.4) | 0.36% | — | Leap13 Premium Addons FOR Elementor | 12/6/2024 | 17/6/2026 | The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several parameters in all versions up to, and including, 4.10.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… |