Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.39% | — | Kubio AI Page BuilderAI | 16/8/2026 | 20/8/2026 | The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Aplazada | Crítica (9.8) | 3.9% | — | User Profile BuilderAI | 15/8/2026 | 20/8/2026 | The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is… | |
| Aplazada | Media (6.4) | 0.41% | — | Fastlinemedia Beaver BuilderAI | 15/8/2026 | 20/8/2026 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module 'button' (Button Code) Setting in all versions up to, and including, 2.10.2.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Media (6.3) | 0.20% | — | Mongodb Odbc DriverMongodb SQL Schema Builder CLI | 12/8/2026 | 29/9/2026 | MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to… | |
| Analizada | Media (6.8) | 0.12% | — | Mongodb SQL Schema Builder CLI | 12/8/2026 | 29/9/2026 | MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext in that diagnostic output. A local user… | |
| Aplazada | Media (6.3) | 0.42% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input. | |
| Aplazada | Media (6.3) | 0.52% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name. | |
| Aplazada | Crítica (9.2) | 0.51% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system. | |
| Aplazada | Baja (1.9) | 1.1% | — | Adolfosalasgomez3011 Slidev-builder-mcpAI | 8/8/2026 | 12/8/2026 | A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command injection. The attack is only possible with… | |
| Aplazada | Alta (8.7) | 0.50% | — | Joomshaper SP Page BuilderAI | 7/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their… | |
| Aplazada | Media (5.3) | 0.29% | — | Cozmoslabs Profile BuilderAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Crocoblock JetformbuilderAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. | |
| Aplazada | Media (6.5) | 0.51% | — | Stylemixthemes Cost Calculator BuilderAI | 5/8/2026 | 12/8/2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action (handler `CCBExportImport::export_calculators()`) in all versions up to, and including, 3.6.17. The handler only verifies a… | |
| Aplazada | Alta (8.1) | 0.38% | — | Codesmiths User Profile BuilderAI | 1/8/2026 | 26/8/2026 | The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported… | |
| Aplazada | Media (5.4) | 0.23% | — | Codeless Page BuilderAI | 1/8/2026 | 26/8/2026 | The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged… | |
| Aplazada | Baja (3.7) | 0.30% | — | BuilderallAI | 1/8/2026 | 26/8/2026 | The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access token. A durable overwrite requires the… | |
| Aplazada | Media (6.5) | 0.37% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 30/7/2026 | 30/7/2026 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request. | |
| Aplazada | Media (6.5) | 0.48% | — | Appcheap APP BuilderAI | 29/7/2026 | 30/7/2026 | A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization Collision combined with symlink following behavior. APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app… | |
| Aplazada | Crítica (9.8) | 1.3% | — | Cost Calculator Builder PROAI | 29/7/2026 | 30/7/2026 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the orderDetails[*].originalValue field, which is injected verbatim into a calculator formula string passed to… | |
| Aplazada | Baja (2.1) | 0.39% | — | Nextlevelbuilder GoclawAI | 28/7/2026 | 28/7/2026 | A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the component jq Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploit has… | |
| Aplazada | Media (6.5) | 0.43% | — | TaskbuilderAI | 28/7/2026 | 28/7/2026 | The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in versions up to, and including, 5.0.9. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 28/7/2026 | Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms. | |
| Aplazada | Alta (8.3) | 0.49% | — | JoomlaAIOllyo SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager. | |
| Aplazada | Alta (8.2) | 0.38% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector. | |
| Aplazada | Crítica (9.2) | 0.39% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 12/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector. |