Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
1951 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.40% | — | Wpdeveloper Essential Addons FOR ElementorAI | 28/8/2026 | 28/8/2026 | Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0. | |
| Aplazada | Media (6.1) | 0.38% | — | Elementskit PROAI | 28/8/2026 | 28/8/2026 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter of the Advanced Search REST endpoint in all versions up to, and including, 4.10.1 due to insufficient input sanitization and output escaping. The REST endpoint at /wp-json/elementskit/v1/advanced-search uses… | |
| Pendiente de análisis | Alta (7) | 0.28% | — | Element Maps-ngAI | 27/8/2026 | 28/8/2026 | A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label… | |
| Aplazada | Alta (8.5) | 0.36% | — | Prolancer ElementAI | 24/8/2026 | 24/8/2026 | Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions. | |
| Aplazada | Alta (7.1) | 0.34% | — | Prolancer ElementAI | 24/8/2026 | 24/8/2026 | Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions. | |
| Aplazada | Media (5.3) | 0.55% | — | Element WEBAIMatrix React SDKAI | 21/8/2026 | 30/9/2026 | Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML without passing it through sanitizedHtmlNode. A malicious homeserver can provide… | |
| Aplazada | Crítica (9.6) | 0.20% | — | Hashthemes Easy Elementor AddonsAI | 20/8/2026 | 24/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7. | |
| Aplazada | Crítica (9) | 2.0% | — | Elementor PROAI | 19/8/2026 | 20/8/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. | |
| Aplazada | Alta (7.2) | 0.27% | — | Animation Addons FOR ElementorAI | 19/8/2026 | 26/8/2026 | The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back. | |
| Aplazada | Media (4.3) | 0.25% | — | Romethemeform FOR ElementorAI | 18/8/2026 | 20/8/2026 | Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Recipe Card Blocks FOR Gutenberg AND ElementorAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions. | |
| Aplazada | Crítica (9.6) | 0.43% | — | Piotnet Addons FOR Elementor PROAI | 18/8/2026 | 20/8/2026 | Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. | |
| Aplazada | Alta (8.8) | 0.63% | — | Royal-elementor-addons Royal Elementor AddonsAI | 16/8/2026 | 20/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render… | |
| Aplazada | Alta (8.1) | 0.38% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/8/2026 | 26/8/2026 | The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a… | |
| Aplazada | Alta (8.6) | 0.25% | — | Element CallAIPosthogAI | 7/8/2026 | 9/9/2026 | Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a `posthog` key in config.json or by the `posthogApiHost` and `posthogApiKey` URL parameters. Several fields of this data (`$initial_person_info`,… | |
| Aplazada | Media (6.5) | 0.22% | — | Brainstormforce Ultimate Addons FOR ElementorAI | 6/8/2026 | 12/8/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Element Pack Elementor AddonsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. | |
| Aplazada | Media (6.5) | 0.44% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 6/8/2026 | 12/8/2026 | Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Ultimate Store KIT Elementor AddonsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | |
| Aplazada | Media (5.3) | 0.35% | — | Element Pack AddonsAI | 6/8/2026 | 12/8/2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email… | |
| Aplazada | Media (6.8) | 0.39% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 4/8/2026 | 26/8/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated… | |
| Aplazada | Media (5.4) | 0.29% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/8/2026 | 12/8/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15. | |
| Aplazada | Media (6.4) | 0.33% | — | Exclusive Addons FOR ElementorAI | 2/8/2026 | 12/8/2026 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.8) | 0.43% | — | Elementpack Element Pack AddonsAI | 2/8/2026 | 26/8/2026 | The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes… | |
| Aplazada | Alta (8.8) | 0.41% | — | Dynamickit FOR ElementorAI | 1/8/2026 | 26/8/2026 | The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries… |