Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

1951 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.40%—Wpdeveloper Essential Addons FOR ElementorAI28/8/202628/8/2026
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
AplazadaMedia (6.1)0.38%—Elementskit PROAI28/8/202628/8/2026
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter of the Advanced Search REST endpoint in all versions up to, and including, 4.10.1 due to insufficient input sanitization and output escaping. The REST endpoint at /wp-json/elementskit/v1/advanced-search uses…
Pendiente de análisisAlta (7)0.28%—Element Maps-ngAI27/8/202628/8/2026
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label…
AplazadaAlta (8.5)0.36%—Prolancer ElementAI24/8/202624/8/2026
Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
AplazadaAlta (7.1)0.34%—Prolancer ElementAI24/8/202624/8/2026
Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
AplazadaMedia (5.3)0.55%—Element WEBAIMatrix React SDKAI21/8/202630/9/2026
Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML without passing it through sanitizedHtmlNode. A malicious homeserver can provide…
AplazadaCrítica (9.6)0.20%—Hashthemes Easy Elementor AddonsAI20/8/202624/8/2026
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.
AplazadaCrítica (9)2.0%—Elementor PROAI19/8/202620/8/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.
AplazadaAlta (7.2)0.27%—Animation Addons FOR ElementorAI19/8/202626/8/2026
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
AplazadaMedia (4.3)0.25%—Romethemeform FOR ElementorAI18/8/202620/8/2026
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
AplazadaAlta (7.1)0.25%—Recipe Card Blocks FOR Gutenberg AND ElementorAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
AplazadaCrítica (9.6)0.43%—Piotnet Addons FOR Elementor PROAI18/8/202620/8/2026
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
AplazadaAlta (8.8)0.63%—Royal-elementor-addons Royal Elementor AddonsAI16/8/202620/8/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render…
AplazadaAlta (8.1)0.38%—Wpdeveloper Essential Addons FOR ElementorAI14/8/202626/8/2026
The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a…
AplazadaAlta (8.6)0.25%—Element CallAIPosthogAI7/8/20269/9/2026
Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a `posthog` key in config.json or by the `posthogApiHost` and `posthogApiKey` URL parameters. Several fields of this data (`$initial_person_info`,…
AplazadaMedia (6.5)0.22%—Brainstormforce Ultimate Addons FOR ElementorAI6/8/202612/8/2026
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
AplazadaMedia (5.3)0.33%—Element Pack Elementor AddonsAI6/8/202612/8/2026
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
AplazadaMedia (6.5)0.44%—Unlimited-elements Unlimited Elements FOR ElementorAI6/8/202612/8/2026
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
AplazadaMedia (6.5)0.27%—Ultimate Store KIT Elementor AddonsAI6/8/202612/8/2026
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
AplazadaMedia (5.3)0.35%—Element Pack AddonsAI6/8/202612/8/2026
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email…
AplazadaMedia (6.8)0.39%—Database FOR Contact Form 7 Wpforms Elementor FormsAI4/8/202626/8/2026
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated…
AplazadaMedia (5.4)0.29%—Unlimited-elements Unlimited Elements FOR ElementorAI3/8/202612/8/2026
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.
AplazadaMedia (6.4)0.33%—Exclusive Addons FOR ElementorAI2/8/202612/8/2026
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.8)0.43%—Elementpack Element Pack AddonsAI2/8/202626/8/2026
The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes…
AplazadaAlta (8.8)0.41%—Dynamickit FOR ElementorAI1/8/202626/8/2026
The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries…