Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

1489 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.4)0.41%—Lockme Oauth2 Calendars IntegrationAI11/7/202613/7/2026
The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output escaping. The register_setting() call on line 197 lacks a sanitize callback,…
AplazadaMedia (4.4)0.34%—Highlighting Code BlockAI10/7/202610/7/2026
The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to…
AplazadaMedia (4.3)0.37%—Kadencewp Gutenberg Blocks With AIAI10/7/202610/7/2026
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check' function permission callback of the 'process_pattern' REST API…
AplazadaMedia (6.5)0.47%—Blocks FOR ACF FieldsAI9/7/20269/7/2026
The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The permission_callback only verifies the generic…
AplazadaCrítica (9.8)1.1%—Creativethemes Blocksy CompanionAI9/7/20269/7/2026
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring…
AplazadaMedia (6.4)0.35%—Block Suspend Report FOR BuddypressAI9/7/20269/7/2026
The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up to and including 3.6.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level access…
AplazadaCrítica (9.2)3.6%💥 ExploitBlocksy Companion PROAI8/7/20268/7/2026
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom…
AplazadaMedia (6.4)0.26%—Posimyth Nexter BlocksAI8/7/20268/7/2026
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (6.4)0.36%—GenerateblocksAI3/7/20266/7/2026
The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaCrítica (10)0.86%—Blocksy Companion PROAI2/7/20262/7/2026
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
AplazadaMedia (5.3)0.58%—Crocoblock JetformbuilderAI2/7/20262/7/2026
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve…
AplazadaMedia (4.3)0.34%—Qodeinteractive QI BlocksAI1/7/20261/7/2026
The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to modify the stored…
AplazadaMedia (4.3)0.45%—Kadence BlocksAI1/7/20261/7/2026
The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.7.7. This is due to a mismatch between the object used for authorization and the object actually accessed in the Optimize_Rest_Controller's…
AplazadaMedia (4.3)0.47%—Kadence BlocksAI1/7/20261/7/2026
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AplazadaMedia (6.4)0.26%—Crocoblock Jetwidgets FOR ElementorAI1/7/20261/7/2026
The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to insufficient output escaping and missing server-side validation of the Animated Box widget's animation_effect setting before it is rendered inside an HTML class…
AplazadaBaja (3.7)0.13%—Hitachi Virtual Storage Platform ONE BlockAI29/6/202629/9/2026
Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.
AplazadaMedia (6.5)0.22%—Themegrill Magazine BlocksAI26/6/202626/6/2026
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.
AplazadaMedia (5.3)0.31%—Blocksy Companion PROAI26/6/202626/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.
AplazadaAlta (8.5)0.58%—Blocksy Companion PROAI26/6/202626/6/2026
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI26/6/202629/6/2026
Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.
AplazadaAlta (8.3)0.30%—Mailchimp BlockAI26/6/202626/6/2026
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
AplazadaMedia (6.4)0.33%—Wpdeveloper Essential BlocksAI25/6/202625/6/2026
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.4)0.32%—MIR Blocks AND ShortcodesAI24/6/202630/6/2026
The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_text') of the 'msc_stats' shortcode in versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on…
AplazadaMedia (4.4)0.34%—Creativethemes Blocksy CompanionAI19/6/202622/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject…
AplazadaMedia (6.4)0.21%—Services Section BlockAI18/6/202618/6/2026
The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'link' Block Attribute in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
Orbitaley — Vulnerabilidades