Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1954 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.39% | — | Element Synapse | 28/5/2026 | 17/6/2026 | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients. Clients could therefore fail to display room history. This vulnerability is fixed in… | |
| Aplazada | Media (5.3) | 0.31% | — | Wpmet Elementskit Elementor Addons LiteAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpmet Elementskit Elementor Addons LiteAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6. | |
| Aplazada | Media (6.5) | 0.28% | — | Xpro Elementor Addons PROAI | 27/5/2026 | 7/10/2026 | The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can… | |
| Aplazada | Alta (8.5) | 0.36% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 25/5/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8. | |
| Aplazada | Alta (8.8) | 0.80% | 💥 PoC | Easy ElementsAI | 22/5/2026 | 23/7/2026 | The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_nopriv_eel_register` AJAX handler iterating the attacker-controlled `custom_meta`… | |
| Aplazada | Media (5) | 0.25% | — | Add-ons.org PDF FOR Elementor Forms AND Drag AND Drop Template BuilderAI | 20/5/2026 | 23/7/2026 | Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through 5.5.1. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Easy Elements FOR ElementorAI | 20/5/2026 | 24/7/2026 | The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can register with. This makes it… | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | Piotnet Addons FOR Elementor PROAI | 19/5/2026 | 24/7/2026 | The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe… | |
| Aplazada | Media (6.4) | 0.32% | — | Royal-elementor-addons Royal Elementor AddonsAI | 14/5/2026 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (6.5) | 0.31% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/5/2026 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function, which only blocks the 'administrator' role. This makes it… | |
| Aplazada | Media (6.4) | 0.26% | — | Posimyth THE Plus Addons FOR ElementorAI | 14/5/2026 | 17/6/2026 | The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to stored cross-site scripting via the `menu_hover_click` parameter of the Navigation Menu Lite widget in all versions up to, and including, 6.4.11 due to insufficient input… | |
| Aplazada | Media (6.5) | 0.55% | — | Unlimited-elements Unlimited ElementsAI | 14/5/2026 | 17/6/2026 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up to and including 2.0.7. This is due to insufficient input sanitization and the use of deprecated escaping functions combined with direct… | |
| Aplazada | Media (4.3) | 0.35% | — | Rtmkit Addons FOR ElementorAI | 13/5/2026 | 17/6/2026 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the save_widget() and reset_all_widgets() functions in all versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with Author-level access and… | |
| Aplazada | Alta (8.5) | 0.36% | — | Xpro Elementor AddonsAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Blind SQL Injection.This issue affects Xpro Elementor Addons: from n/a through <= 1.5.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Royal-elementor-addons Royal Elementor AddonsAI | 7/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a before 1.7.1053. | |
| Aplazada | Media (5.3) | 0.33% | — | Wedevs Happy Addons FOR ElementorAI | 7/5/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Happy Addons for Elementor: from n/a through 3.20.8. | |
| Aplazada | Media (5.3) | 0.31% | — | Royal-elementor-addons Royal Elementor AddonsAI | 7/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before 1.7.1053. | |
| Aplazada | Media (6.5) | 0.59% | — | Wpmet ElementskitAI | 5/5/2026 | 17/6/2026 | The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `Live_Action::reset()` function in all versions up to, and including, 3.8.2 The function is hooked to the WordPress `init` action and triggers when both `post` and… | |
| Aplazada | Alta (7.2) | 0.42% | — | Royal-elementor-addons Royal Elementor AddonsAI | 5/5/2026 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked… | |
| Aplazada | Media (5.4) | 0.24% | — | Leap13 Premium Addons FOR ElementorAI | 2/5/2026 | 17/6/2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_svg' parameter in versions up to, and including, 4.11.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.2) | 0.48% | — | Royal-elementor-addons Royal Elementor AddonsAI | 2/5/2026 | 18/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query… | |
| Aplazada | Media (6.4) | 0.36% | — | ElementorAI | 1/5/2026 | 17/6/2026 | The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data meta field in versions up to, and including, 4.0.4. This is due to insufficient input sanitization when processing form-encoded REST API requests. The plugin registers the _elementor_data meta field… | |
| Aplazada | Media (6.5) | 0.22% | — | Codexthemes Thegem Theme ElementsAI | 27/4/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows DOM-Based XSS.This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1. | |
| Aplazada | Media (6.4) | 0.35% | — | Royal-elementor-addons Royal Elementor AddonsAI | 24/4/2026 | 14/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of… |