Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3246▲ 685 respecto a la semana anterior
Críticas / altas1521▲ 128 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
1874 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.21% | — | Stylemixthemes Masterstudy LMSAI | 22/9/2025 | 17/6/2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Leveraging Race Conditions.This issue affects MasterStudy LMS: from n/a through <= 3.6.20. | |
| Aplazada | Media (6.5) | 0.22% | — | Stylemixthemes Masterstudy LMSAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from n/a through <= 3.6.20. | |
| Aplazada | Alta (8.8) | 0.17% | — | Purethemes Workscout-coreAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Cross Site Request Forgery.This issue affects WorkScout-Core: from n/a through < 1.7.06. | |
| Aplazada | Media (4.3) | 0.25% | — | Hashthemes Smart BlocksAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in hashthemes Smart Blocks smart-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Blocks: from n/a through <= 2.4. | |
| Aplazada | Alta (7.5) | 0.51% | — | Hashthemes Easy Elementor AddonsAI | 22/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hashthemes Easy Elementor Addons easy-elementor-addons allows PHP Local File Inclusion.This issue affects Easy Elementor Addons: from n/a through <= 2.2.8. | |
| Modificada | Crítica (9.8) | 0.28% | — | Vibethemes Wordpress Learning Management System | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in VibeThemes WPLMS wplms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLMS : from n/a through <= 4.970. | |
| Aplazada | Media (6.5) | 0.21% | — | Bdthemes ZoloblocksAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes ZoloBlocks zoloblocks allows DOM-Based XSS.This issue affects ZoloBlocks: from n/a through <= 2.3.12. | |
| Aplazada | Media (6.5) | 0.21% | — | Bdthemes Ultimate Store KITAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.8.6. | |
| Aplazada | Media (5.3) | 0.28% | — | Javothemes Javo CoreAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in javothemes Javo Core javo-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Javo Core: from n/a through <= 3.0.0.266. | |
| Aplazada | Media (4.3) | 0.15% | — | Themespride Advanced Appointment Booking SchedulingAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themespride Advanced Appointment Booking & Scheduling advanced-appointment-booking-scheduling allows Cross Site Request Forgery.This issue affects Advanced Appointment Booking & Scheduling: from n/a through <= 2.1. | |
| Aplazada | Media (5.3) | 0.24% | — | Cozythemes Cozy BlocksAI | 22/9/2025 | 30/9/2026 | Neutralización Incorrecta de Etiquetas HTML Relacionadas con Scripts en una Página Web (XSS Básico) vulnerabilidad en CozyThemes Cozy Blocks permite la Inyección de Código. Este problema afecta a Cozy Blocks: desde n/a hasta 2.1.29. | |
| Aplazada | Media (6.4) | 0.25% | — | Creativethemes Blocksy CompanionAI | 17/9/2025 | 17/6/2026 | El plugin Blocksy Companion para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode `blocksy_newsletter_subscribe` del plugin en todas las versiones hasta la 2.1.10, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes en los atributos proporcionados por el… | |
| Aplazada | Alta (7.5) | 0.63% | — | Catchthemes Catch Dark ModeAI | 17/9/2025 | 25/9/2026 | El plugin Catch Dark Mode para WordPress es vulnerable a la inclusión local de ficheros en todas las versiones hasta la 2.0, inclusive, a través del shortcode 'catch_dark_mode'. Esto hace posible que atacantes autenticados, con acceso de nivel Colaborador o superior, incluyan y ejecuten ficheros .php arbitrarios en el… | |
| Aplazada | Media (5.4) | 0.35% | — | Mythemeshop MY WP TranslateAI | 11/9/2025 | 17/6/2026 | The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtswpt_remove_plugin() and ajax_update_export_code() functions in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (8.8) | 0.31% | — | Mythemeshop MY WP TranslateAI | 11/9/2025 | 30/9/2026 | El plugin My WP Translate para WordPress es vulnerable a la modificación no autorizada de datos que puede conducir a una escalada de privilegios debido a una comprobación de capacidad faltante en la función ajax_import_strings() en todas las versiones hasta la 1.1, inclusive. Esto hace posible que atacantes… | |
| Modificada | Media (5.4) | 0.17% | — | Hasthemes Shoplentor | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems ShopLentor woolentor-addons allows Stored XSS.This issue affects ShopLentor: from n/a through <= 3.2.0. | |
| Aplazada | Media (6.4) | 0.24% | — | Sktthemes SKT Addons FOR ElementorAI | 6/9/2025 | 17/6/2026 | The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.24% | — | Athemes Addons FOR ElementorAI | 6/9/2025 | 17/6/2026 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.23% | — | Stylemixthemes Masterstudy LMSAI | 5/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from n/a through <= 3.6.15. | |
| Aplazada | Crítica (9.8) | 0.44% | — | Axiomthemes Smart SEOAI | 5/9/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue affects smart SEO: from n/a through <= 4.0. | |
| Aplazada | Media (6.5) | 0.29% | — | Premiumbizthemes Simple Price CalculatorAI | 5/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in premiumbizthemes Simple Price Calculator simple-price-calculator-basic allows Retrieve Embedded Sensitive Data.This issue affects Simple Price Calculator: from n/a through <= 1.3. | |
| Aplazada | Alta (7.1) | 0.13% | — | Otwthemes Popping Sidebars AND Widgets LightAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Popping Sidebars and Widgets Light popping-sidebars-and-widgets-light allows Reflected XSS.This issue affects Popping Sidebars and Widgets Light: from n/a through <= 1.27. | |
| Aplazada | Media (5.9) | 0.22% | — | Otwthemes Widgetize Pages LightAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Stored XSS.This issue affects Widgetize Pages Light: from n/a through <= 3.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Vwthemes Ibtana Ecommerce Product AddonsAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana – Ecommerce Product Addons ibtana-ecommerce-product-addons allows DOM-Based XSS.This issue affects Ibtana – Ecommerce Product Addons: from n/a through <= 0.4.7.6. | |
| Aplazada | Media (4.3) | 0.24% | — | Desertthemes SoftmeAI | 5/9/2025 | 5/10/2026 | Vulnerabilidad por autorización faltante en desertthemes SoftMe softme permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a SoftMe: desde n/a hasta menor o igual a 1.1.27. |