Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
1954 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | TIM Strifler Exclusive Addons ElementorAI | 26/6/2026 | 26/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8. | |
| Aplazada | Media (6.5) | 0.37% | — | ElementorAI | 25/6/2026 | 25/6/2026 | Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. | |
| Aplazada | Alta (8.1) | 1.0% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 20/6/2026 | 22/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the… | |
| Pendiente de análisis | Alta (8.5) | 0.18% | — | Wondershare PdfelementAI | 19/6/2026 | 29/9/2026 | Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot. | |
| Aplazada | Alta (7.1) | 0.25% | — | Royal-elementor-addons Royal Elementor Addons PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. | |
| Aplazada | Alta (8.8) | 0.50% | — | Powerpack PRO FOR ElementorAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Element Pack PROAI | 17/6/2026 | 17/6/2026 | Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpzoom Addons FOR ElementorAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | ElementraAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. | |
| Aplazada | Crítica (9.9) | 0.48% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 17/6/2026 | 17/6/2026 | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | 💥 PoC | Integration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Kingaddons King Addons FOR ElementorAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Product Filter Widget FOR ElementorAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor <= 1.0.6 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpdeveloper Essential Addons FOR ElementorAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions. | |
| Aplazada | Media (4.3) | 0.18% | — | Hashthemes Hash ElementsAI | 12/6/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data. This issue affects Hash Elements: from n/a through 1.5.4. | |
| Aplazada | Media (5.4) | 0.18% | — | Themehunk Contact Form AND Lead Form Elementor BuilderAI | 11/6/2026 | 26/9/2026 | Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Contact Form & Lead Form Elementor Builder: from n/a through 1.8.4. | |
| Aplazada | Media (6.4) | 0.36% | — | Athemes Addons FOR ElementorAI | 10/6/2026 | 23/7/2026 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (6.4) | 0.15% | — | Animation Addons FOR ElementorAI | 10/6/2026 | 23/7/2026 | The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the multiple parameters in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.4) | 0.43% | — | Prime Elementor AddonsAI | 9/6/2026 | 23/7/2026 | The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.1) | 0.21% | — | Product Filter Widget FOR ElementorAI | 9/6/2026 | 23/7/2026 | The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (5.3) | 0.56% | 💥 PoC | Wpdeveloper Essential Addons FOR ElementorAI | 6/6/2026 | 23/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.38% | — | Master-addons Master Addons FOR ElementorAI | 6/6/2026 | 23/7/2026 | The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension) in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output… | |
| Aplazada | Media (5.4) | 0.25% | — | ElementorAI | 2/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through 4.1.0. | |
| Aplazada | Media (6.4) | 0.33% | — | Theplus Plus Addons FOR ElementorAI | 29/5/2026 | 21/7/2026 | The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the carousel_direction value is… | |
| Analizada | Media (6.8) | 0.13% | — | Element Synapse | 28/5/2026 | 17/6/2026 | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1. |