Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2834▲ 81 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

1863 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.51%—Vlthemes LeedoAI13/7/202613/7/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VLThemes Leedo leedo allows PHP Local File Inclusion.This issue affects Leedo: from n/a through <= 3.0.0.
AplazadaAlta (7.5)0.51%—Elated-themes FlowAI13/7/202613/7/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Flow flow allows PHP Local File Inclusion.This issue affects Flow: from n/a through <= 1.8.
AplazadaAlta (7.5)0.51%—Edge-themes AaltoAI13/7/202613/7/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Aalto aalto allows PHP Local File Inclusion.This issue affects Aalto: from n/a through <= 1.8.
AplazadaAlta (8.8)0.23%—Purethemes Workscout-coreAI13/7/202613/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08.
AplazadaAlta (8.2)0.32%—Favethemes Houzez Login RegisterAI13/7/202613/7/2026
Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.
AplazadaCrítica (9.8)0.56%—Axiomthemes 777 Triple-sevenAI13/7/202613/7/2026
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
AplazadaAlta (7.5)0.39%—Uxthemes FlatsomeAI13/7/202613/7/2026
Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5.
AplazadaAlta (7.1)0.25%—Uxthemes FlatsomeAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: from n/a through <= 3.20.5.
AplazadaMedia (6.4)0.23%—Bdthemes Instant Image GeneratorAI13/7/202613/7/2026
Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects Instant Image Generator: from n/a through <= 2.1.4.
AplazadaMedia (5.3)0.58%—Stylemixthemes Cost Calculator BuilderAI11/7/202613/7/2026
The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). This makes it possible for unauthenticated attackers to extract the plaintext Stripe secret key, Razorpay secret key, and PayPal client_secret embedded…
AplazadaCrítica (9.8)1.1%—Creativethemes Blocksy CompanionAI9/7/20269/7/2026
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring…
AplazadaAlta (8.8)0.44%—Elegantthemes Divi Form BuilderAI9/7/20269/7/2026
The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and…
AplazadaAlta (7.5)0.46%—Imithemes EventerAI8/7/20268/7/2026
The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers…
AplazadaCrítica (9.8)0.48%—Imithemes EventerAI8/7/20268/7/2026
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field when a user requests a password reset. The plaintext key stored in…
AplazadaAlta (8.8)0.20%—Xplodedthemes WpideAI2/7/20262/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.
AplazadaMedia (6.5)0.34%—Uxthemes FlatsomeAI2/7/20262/7/2026
Contributor Broken Access Control in Flatsome <= 3.20.5 versions.
AplazadaMedia (4.3)0.27%—Uxthemes FlatsomeAI2/7/20262/7/2026
Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.
AplazadaCrítica (9.9)0.48%—Zozothemes ZegenAI2/7/20262/7/2026
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
AplazadaMedia (4.3)0.39%—Envothemes Templates Widgets FOR Elementor AND WoocommerceAI2/7/20262/7/2026
The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a…
AplazadaAlta (8.5)0.36%—Afthemes WP Post AuthorAI26/6/202626/6/2026
Contributor SQL Injection in WP Post Author <= 3.9.1 versions.
AplazadaMedia (4.3)0.25%—Stylemixthemes Masterstudy LMSAI26/6/202626/6/2026
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
AplazadaAlta (8.8)0.52%—PHPAIInspirythemes RealhomesAI26/6/202626/6/2026
Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.
AplazadaMedia (4.4)0.34%—Creativethemes Blocksy CompanionAI19/6/202622/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject…
AplazadaAlta (8.1)0.56%—Stylemixthemes MotorsAI17/6/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.
AplazadaCrítica (9.8)0.56%—Thrivethemes Thrive ApprenticeAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.