Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.40% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Thrive Quiz BuilderAI | 23/7/2026 | 23/7/2026 | Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Whitestudio Easy Form BuilderAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Funnelkit Funnel Builder PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Funnelkit Funnel Builder PROAI | 23/7/2026 | 23/7/2026 | Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions. | |
| Aplazada | Crítica (9.4) | 0.38% | — | Joomla Page Builder CKAI | 22/7/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE. | |
| Aplazada | Alta (8.8) | 0.51% | — | Free Builder FOR ElementorAI | 21/7/2026 | 21/7/2026 | The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Whitestudio Easy Form BuilderAI | 21/7/2026 | 21/7/2026 | The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in… | |
| Aplazada | Crítica (9.1) | 0.40% | — | Joomlack Page Builder CKAI | 20/7/2026 | 23/7/2026 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views. | |
| Aplazada | Media (6.9) | 0.43% | — | Themexpert Quix Page BuilderAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses. | |
| Aplazada | Alta (8.7) | 0.41% | — | Themexpert Quix Page BuilderAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions. | |
| Aplazada | Media (5.1) | 0.42% | — | Themexpert Quix Page BuilderAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users. | |
| Aplazada | Alta (8.6) | 0.42% | — | Themexpert Quix Page BuilderAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output +… | |
| Aplazada | Alta (8.7) | 0.52% | — | Themexpert Quix Page BuilderAIJoomlaAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files.… | |
| Aplazada | Alta (8.9) | 0.53% | — | Themexpert Quix Page BuilderAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nextlevelbuilder GoclawAI | 19/7/2026 | 20/7/2026 | A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.46% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This affects the function CheckSSRF/isPrivateIP of the file internal/tools/web_shared.go of the component web_fetch. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 22/7/2026 | A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Baja (1.9) | 0.31% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit has been released to the public and may… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.40% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the function matchesAllowlist/extractBin of the file internal/tools/exec_approval.go. Executing a manipulation can lead to incorrectly-resolved name. The attack may be performed from remote. The exploit has been publicly… | |
| Aplazada | Baja (2.1) | 0.40% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 21/7/2026 | A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The… | |
| Aplazada | Alta (8.7) | 0.40% | — | Themexpert Quix Page Builder PROAIJoomlaAI | 16/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection. | |
| Aplazada | Media (4.3) | 0.47% | — | Themify BuilderAI | 16/7/2026 | 18/7/2026 | The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (6.1) | 0.25% | — | Header Footer Builder FOR ElementorAI | 16/7/2026 | 16/7/2026 | The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import action (it allows any edit_posts user), so a Contributor can import a template containing an Elementor HTML widget configured to display site-wide, injecting JavaScript… |