Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
1426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.13% | — | Export Import Wpbakery Page BuilderAI | 12/9/2026 | 14/9/2026 | The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that… | |
| Aplazada | Media (6.5) | 0.22% | — | Visualcomposer Website BuilderAI | 11/9/2026 | 11/9/2026 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Bold Page BuilderAI | 11/9/2026 | 11/9/2026 | Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions. | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI | 11/9/2026 | 11/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users… | |
| Aplazada | Media (6.8) | 0.43% | — | AI BuilderAI | 11/9/2026 | 11/9/2026 | The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary JavaScript that will execute in the browser of anyone who views the post, including the… | |
| Aplazada | Media (6.5) | 0.26% | — | WOO PDF Invoice BuilderAI | 11/9/2026 | 11/9/2026 | The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8. This is due to the InspectOrder() AJAX handler (woocommerce-pdf-invoice-ajax.php:513), registered on… | |
| Aplazada | Media (6.9) | 0.54% | — | Joomlart T4 Page BuilderAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captcha (when no captcha plugin is enabled) and has no rate limiting. The attacker… | |
| Aplazada | Media (4.3) | 0.20% | — | Builderall Cheetah FOR WPAI | 10/9/2026 | 11/9/2026 | The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disable() function in versions up to, and including, 3.0.2. The wp_ajax_ba_cheetah_disable AJAX handler is registered without any capability or nonce verification, and the… | |
| Aplazada | Media (6.4) | 0.19% | — | BuilderallAI | 10/9/2026 | 10/9/2026 | The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Media (6.4) | 0.19% | — | BuilderallAI | 10/9/2026 | 10/9/2026 | The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bg_video_service_url' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (4.3) | 0.43% | — | Checkout Custom Fields Builder FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.27% | — | Fastlinemedia Beaver BuilderAI | 8/9/2026 | 8/9/2026 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.10.3.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.… | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetformbuilderAI | 8/9/2026 | 8/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions. | |
| Aplazada | Alta (7.2) | 0.42% | — | Codesigner User Profile BuilderAI | 7/9/2026 | 9/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (4.8) | 0.15% | — | Crocoblock JetformbuilderAI | 6/9/2026 | 8/9/2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender.… | |
| Aplazada | Media (6.5) | 0.21% | — | Crocoblock JetformbuilderAI | 6/9/2026 | 8/9/2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion… | |
| Aplazada | Media (6.8) | 0.43% | — | Bold-themes Bold Page BuilderAI | 6/9/2026 | 8/9/2026 | The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page. | |
| Aplazada | Media (6.8) | 0.43% | — | Bold-themes Bold Page BuilderAI | 5/9/2026 | 8/9/2026 | The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page. | |
| Aplazada | Media (6.8) | 0.43% | — | Bold-themes Bold Page BuilderAI | 5/9/2026 | 8/9/2026 | The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link. | |
| Aplazada | Media (4.7) | 0.17% | — | Crocoblock JetformbuilderAI | 5/9/2026 | 8/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other… | |
| Aplazada | Alta (7.5) | 0.32% | — | Jetformbuilder Dynamic Blocks Form BuilderAI | 5/9/2026 | 8/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft… | |
| Aplazada | Media (6.1) | 0.17% | — | Fastlinemedia Beaver BuilderAI | 5/9/2026 | 8/9/2026 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, 2.11.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.83% | — | AI Website BuilderAI | 4/9/2026 | 8/9/2026 | The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory,… | |
| Analizada | Media (5.3) | 0.33% | — | Dxpr Builder Project Dxpr Builder | 2/9/2026 | 9/9/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1. | |
| Aplazada | Alta (8.8) | 0.45% | — | Ays-pro FAQ BuilderAI | 2/9/2026 | 3/9/2026 | The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a… |