Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

93 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.51%—Kadencewp Gutenberg Blocks With AI28/3/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through <= 3.2.19.
ModificadaMedia (5.4)0.53%—Kadencewp Gutenberg Blocks With AI13/3/202417/6/2026
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the htmlTag attribute in all versions up to, and including, 3.2.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaAlta (8.8)0.61%—Jorisvm JVM Gutenberg Rich Text Icons29/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Joris van Montfort JVM Gutenberg Rich Text Icons.This issue affects JVM Gutenberg Rich Text Icons: from n/a through 1.2.3.
ModificadaMedia (5.4)0.79%—WordpressWordpress Gutenberg13/10/202317/6/2026
Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.
ModificadaMedia (5.4)0.36%—Wpdownloadmanager Gutenberg Blocks FOR Wordpress Download Manager3/5/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions.
ModificadaMedia (4.3)0.28%—Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks27/3/202317/6/2026
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaBaja (3)0.70%—Gutenberg Project Gutenberg30/7/202217/6/2026
The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents are…
ModificadaMedia (5.4)0.65%—PDF Viewer Block FOR Gutenberg Project PDF Viewer Block FOR Gutenberg18/10/202117/6/2026
The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
ModificadaMedia (4.3)0.76%—Wpxpo Postx - Gutenberg Blocks FOR Post Grid27/9/202117/6/2026
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.
ModificadaMedia (5.4)0.53%—Wpxpo Postx - Gutenberg Blocks FOR Post Grid27/9/202117/6/2026
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.
ModificadaMedia (5.4)0.55%—Wpxpo Postx - Gutenberg Blocks FOR Post Grid27/9/202117/6/2026
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.
ModificadaMedia (6.5)0.72%—Wpxpo Postx - Gutenberg Blocks FOR Post Grid27/9/202117/6/2026
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.
ModificadaMedia (5.4)0.62%—Wpzoom Recipe Card Blocks FOR Gutenberg & Elementor27/9/202117/6/2026
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site…
ModificadaMedia (6.1)0.83%—Wpzoom Recipe Card Blocks FOR Gutenberg & Elementor27/9/202117/6/2026
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (5.3)29%💥 ExploitGutenberg Template Library & Redux Framework2/9/202117/6/2026
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash…
ModificadaMedia (6.5)1.3%—Gutenberg Template Library & Redux Framework2/9/202117/6/2026
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissions_callback` used in this file only checked for the…
ModificadaAlta (8.8)1.6%—Cyberchimps Gutenberg & Elementor Templates Importer FOR Responsive23/4/202017/6/2026
The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests.
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Orbitaley — Vulnerabilidades