Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.33% | — | Theinnovs Elementscss Addons FOR ElementorAI | 1/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in TheInnovs ElementsCSS Addons for Elementor css-for-elementor allows Server Side Request Forgery.This issue affects ElementsCSS Addons for Elementor: from n/a through <= 1.0.8.9. | |
| Aplazada | Media (6.5) | 0.36% | — | Athemeart News Magazine AND Blog ElementsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemeArt News, Magazine and Blog Elements news-magazine-and-blog-elements allows Stored XSS.This issue affects News, Magazine and Blog Elements: from n/a through <= 1.3. | |
| Analizada | Media (5.4) | 0.27% | — | Wpmet Elementskit Elementor Addons | 29/3/2025 | 17/6/2026 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Media (5.4) | 0.29% | — | Techeshta Card Elements FOR Elementor | 27/2/2025 | 17/6/2026 | The Card Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Profile Card widget in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Media (5.4) | 0.35% | — | Unlimited-elements Unlimited Elements FOR Elementor | 20/2/2025 | 17/6/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (5.3) | 0.49% | — | Wpmet Elementskit Elementor Addons | 19/2/2025 | 17/6/2026 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such… | |
| Aplazada | Crítica (9.8) | 0.52% | — | Seventhqueen K ElementsAI | 18/2/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/a through < 5.4.0. | |
| Analizada | Media (5.4) | 0.36% | — | Wpmet Elementskit Elementor Addons | 15/2/2025 | 17/6/2026 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.5) | 0.31% | — | Adobe Photoshop Elements | 11/2/2025 | 17/6/2026 | Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.4) | 0.26% | — | Wpmet Elementskit | 28/1/2025 | 17/6/2026 | The ElementsKit Pro plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Crítica (9.8) | 1.3% | — | G5plus Ultimate Bootstrap Elements FOR Elementor | 24/1/2025 | 17/6/2026 | The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass… | |
| Analizada | Media (5.4) | 0.29% | — | Crocoblock Jetelements | 21/1/2025 | 17/6/2026 | The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access… | |
| Analizada | Media (4.3) | 0.52% | — | Webtechstreet Elementor Addon Elements | 15/1/2025 | 17/6/2026 | The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Media (5.4) | 0.31% | — | Unlimited-elements Unlimited Elements FOR Elementor | 9/1/2025 | 17/6/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (6.5) | 0.25% | — | Hashthemes Hash Elements | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Hash Elements hash-elements.This issue affects Hash Elements: from n/a through <= 1.5.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Theinnovs Elementscss Addons FOR ElementorAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TheInnovs ElementsCSS Addons for Elementor css-for-elementor allows Stored XSS.This issue affects ElementsCSS Addons for Elementor: from n/a through <= 1.0.8.9. | |
| Aplazada | Media (4.1) | 0.39% | — | Envato ElementsAI | 7/1/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Envato Envato Elements allows Server Side Request Forgery.This issue affects Envato Elements: from n/a through 2.0.14. | |
| Analizada | Media (4.3) | 0.43% | — | Quomodosoft Elementsready | 17/12/2024 | 17/6/2026 | The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private,… | |
| Aplazada | Media (6.4) | 0.30% | — | Visualmodo ElementsAI | 14/12/2024 | 17/6/2026 | The Visualmodo Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Analizada | Media (5.4) | 0.35% | — | Unlimited-elements Unlimited Elements FOR Elementor | 12/12/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all versions up to, and including, 1.5.126 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.33% | — | Quomodosoft Elementsready | 9/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quomodosoft ElementsReady Addons for Elementor element-ready-lite allows DOM-Based XSS.This issue affects ElementsReady Addons for Elementor: from n/a through <= 6.4.7. | |
| Aplazada | Media (5.3) | 0.50% | — | Premio MY Sticky ElementsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Premio My Sticky Elements mystickyelements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Sticky Elements: from n/a through <= 2.1.3. | |
| Aplazada | Media (6.5) | 0.33% | — | Generic Elements FOR Elementor Generic ElementsAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Uddin Generic Elements generic-elements-for-elementor allows DOM-Based XSS.This issue affects Generic Elements: from n/a through <= 1.2.5. | |
| Aplazada | Media (5.5) | 0.19% | — | Withsecure Elements AgentAIWithsecure MDRAIWithsecure Elements Client SecurityAI | 29/11/2024 | 17/6/2026 | WithSecure Elements Agent for Mac before 24.3, MDR before 24.3, and Elements Client Security for Mac before 16.10 allow a remote Denial of Service. | |
| Modificada | Media (5.4) | 0.51% | — | Voidcoders Wpbakery Visual Composer Whmcs Elements | 21/11/2024 | 17/6/2026 | The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's void_wbwhmcse_laouts_search shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… |