Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.31% | — | Solverwp Elementor Portfolio BuilderAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SolverWp Elementor Portfolio Builder portfolio-builder-elementor allows DOM-Based XSS.This issue affects Elementor Portfolio Builder: from n/a through <= 1.0.0. | |
| Aplazada | Media (5.9) | 0.30% | — | Portfoliohub Wordpress Portfolio BuilderAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in portfoliohub WordPress Portfolio Builder – Portfolio Gallery uber-grid allows Stored XSS.This issue affects WordPress Portfolio Builder – Portfolio Gallery: from n/a through <= 1.1.7. | |
| Aplazada | Media (6.1) | 0.46% | — | Ays-pro FAQ BuilderAI | 28/11/2024 | 17/6/2026 | The FAQ Builder AYS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_faq_tab' parameter in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Media (5.4) | 0.37% | — | Elementor Website Builder | 26/11/2024 | 17/6/2026 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (4.1) | 0.50% | — | Taskbuilder | 21/11/2024 | 17/6/2026 | The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks | |
| Aplazada | Media (4.3) | 0.47% | — | Theme Builder FOR ElementorAI | 21/11/2024 | 17/6/2026 | The Theme Builder For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level… | |
| Modificada | Media (5.4) | 0.22% | — | Wpzoom Beaver Builder Addons | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Beaver Builder Addons by WPZOOM wpzoom-addons-for-beaver-builder allows Stored XSS.This issue affects Beaver Builder Addons by WPZOOM: from n/a through <= 1.3.4. | |
| Modificada | Media (4.8) | 0.26% | — | Fastlinemedia Beaver Builder | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Stored XSS.This issue affects Beaver Builder: from n/a through <= 2.8.3.7. | |
| Modificada | Alta (8.8) | 1.9% | — | Bold-themes Bold Page Builder | 19/11/2024 | 17/6/2026 | Missing Authorization vulnerability in boldthemes Bold Page Builder bold-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bold Page Builder: from n/a through <= 5.1.3. | |
| Modificada | Media (5.4) | 0.24% | — | Themify Builder | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Stored XSS.This issue affects Themify Builder: from n/a through <= 7.6.5. | |
| Aplazada | Alta (7.5) | 7.5% | 💥 Exploit | Redefiningtheweb PDF Generator Addon FOR Elementor Page BuilderAI | 16/11/2024 | 17/6/2026 | The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain… | |
| Aplazada | Crítica (9.8) | 0.98% | 💥 PoC | Medmatech Matix Popup BuilderAI | 14/11/2024 | 17/6/2026 | Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue affects Matix Popup Builder: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.3) | 0.50% | — | Boostify Header Footer BuilderAI | 13/11/2024 | 17/6/2026 | The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.6 via the 'bhf' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level… | |
| Modificada | Media (4.3) | 0.48% | — | Staxwp Buddybuilder | 13/11/2024 | 17/6/2026 | The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.8) | 0.27% | — | Bricksable FOR Bricks Builder | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable Bricksable for Bricks Builder bricksable allows Stored XSS.This issue affects Bricksable for Bricks Builder: from n/a through <= 1.6.59. | |
| Aplazada | Alta (7.1) | 0.27% | — | Biplob018 Team Showcase AND Slider Team Members BuilderAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biplob018 Team Showcase and Slider – Team Members Builder team-showcase-ultimate allows Reflected XSS.This issue affects Team Showcase and Slider – Team Members Builder: from n/a through <= 1.3. | |
| Analizada | Media (5.4) | 0.30% | — | Brainstormforce Elementor Header & Footer Builder | 8/11/2024 | 17/6/2026 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and… | |
| Modificada | Media (5.4) | 0.24% | — | Hasthemes HT Builder | 4/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder for Elementor ht-builder allows Stored XSS.This issue affects HT Builder – WordPress Theme Builder for Elementor: from n/a through <= 1.3.0. | |
| Modificada | Alta (7.5) | 0.45% | — | Stacksmarket Stacks Mobile APP Builder | 4/11/2024 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. | |
| Modificada | Crítica (9.8) | 0.51% | — | Stacksmarket Stacks Mobile APP Builder | 4/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. | |
| Aplazada | Media (4.3) | 0.34% | — | Pagebuildersandwich Page Builder SandwichAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WordPress Page Builder Sandwich Team Page Builder Sandwich – Front-End Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page Builder Sandwich – Front-End Page Builder: from n/a through 5.1.0. | |
| Modificada | Crítica (9.8) | 0.29% | — | Greenshiftwp Greenshift - Animation AND Page Builder Blocks | 30/10/2024 | 17/6/2026 | Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 9.7. | |
| Analizada | Media (5.4) | 0.35% | — | Fastlinemedia Beaver Builder | 29/10/2024 | 17/6/2026 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.4) | 0.28% | — | Chef Habitat Builder APIAI | 28/10/2024 | 17/6/2026 | The Chef Habitat builder-api on-prem-builder package with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect object reference (IDOR) by un-authorized deletion of personal token. Habitat builder consumes builder-api habitat package as a dependency and the vulnerability was… | |
| Modificada | Media (5.4) | 0.27% | — | Redefiningtheweb PDF Generator Addon FOR Elementor Page Builder | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder pdf-generator-addon-for-elementor-page-builder allows Stored XSS.This issue affects PDF Generator Addon for Elementor Page Builder: from n/a through <=… |