Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.51% | — | Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates) | 9/7/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.50% | — | Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates) | 9/7/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Modificada | Media (5.4) | 0.35% | — | Apollo13themes Rife Elementor Extensions & Templates | 2/7/2024 | 17/6/2026 | The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute within the plugin's Writing Effect Headline widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Modificada | Media (6.5) | 0.40% | — | Brainstormforce Starter Templates | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Premium Starter Templates, Brainstorm Force Starter Templates astra-sites.This issue affects Premium Starter Templates: from n/a through 3.2.5; Starter Templates: from n/a through 3.2.5. | |
| Modificada | Media (5.4) | 0.40% | — | Brainstormforce Elementor - Header, Footer & Blocks Template | 13/6/2024 | 17/6/2026 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (4.8) | 0.25% | — | Wpgogo Custom Field Template | 11/6/2024 | 17/6/2026 | The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Modificada | Media (5.4) | 0.26% | — | Wpgogo Custom Field Template | 11/6/2024 | 17/6/2026 | The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom field name column in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied custom fields. This makes it possible for authenticated attackers… | |
| Modificada | Media (4.3) | 0.29% | — | Wpgogo Custom Field Template | 11/6/2024 | 17/6/2026 | The Custom Field Template plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the 'cft' shortcode. This makes it possible for authenticated attackers with contributor access and above, to extract sensitive data including arbitrary post metadata. | |
| Modificada | Media (5.4) | 0.26% | — | Wpgogo Custom Field Template | 11/6/2024 | 17/6/2026 | The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cpt' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied post meta. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.8) | 0.32% | — | Bosathemes Bosa Elementor Addons AND Templates FOR Woocommerce | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Bosa Themes Bosa Elementor Addons and Templates for WooCommerce.This issue affects Bosa Elementor Addons and Templates for WooCommerce: from n/a through 1.0.12. | |
| Analizada | Media (5.4) | 0.26% | — | Templatesnext Onepager | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TemplatesNext TemplatesNext OnePager allows Stored XSS.This issue affects TemplatesNext OnePager: from n/a through 1.3.3. | |
| Aplazada | Media (6.4) | 0.34% | — | Wpkoi Templates FOR ElementorAI | 22/5/2024 | 17/6/2026 | The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id', 'mixColor', 'backgroundColor', 'saveInCookies', and 'autoMatchOsTheme' parameters in all versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.4) | 0.45% | — | Starter TemplatesAI | 14/5/2024 | 17/6/2026 | The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.42% | — | Envothemes Envo's Elementor Templates & Widgets FOR Woocommerce | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce allows Stored XSS.This issue affects Envo's Elementor Templates & Widgets for WooCommerce: from n/a through 1.4.8. | |
| Aplazada | Media (4.3) | 0.57% | — | Starter TemplatesAI | 14/5/2024 | 17/6/2026 | The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attackers, with contributor-level access and above, to make web… | |
| Aplazada | Media (6.4) | 0.45% | — | Template KIT ImportAI | 9/4/2024 | 17/6/2026 | The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload functionality in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access and above, to… | |
| Aplazada | Alta (7.1) | 0.32% | — | Brainstormforce Starter Templates Elementor Wordpress Beaver Builder TemplatesAIBrainstormforce Premium Starter TemplatesAI | 28/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates, Brainstorm Force Premium Starter Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4; Premium Starter Templates:… | |
| Aplazada | Media (6.5) | 0.32% | — | Wpgogo Custom Field TemplateAI | 15/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template allows Stored XSS.This issue affects Custom Field Template: from n/a through 2.6. | |
| Modificada | Media (5.4) | 0.32% | — | Wpkoi Templates FOR Elementor | 7/3/2024 | 17/6/2026 | The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget in all versions up to, and including, 2.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Media (5.4) | 0.80% | — | Golang Html/templateAI | 5/3/2024 | 17/6/2026 | If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates. | |
| Modificada | Media (4.3) | 0.34% | — | Sktthemes SKT Templates | 29/2/2024 | 17/6/2026 | The SKT Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saveSktbuilderPageData' function in all versions up to, and including, 4.1. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary… | |
| Modificada | Media (4.3) | 0.32% | — | Envothemes Envo's Elementor Templates & Widgets FOR Woocommerce | 28/2/2024 | 17/6/2026 | The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4.4. This is due to missing or incorrect nonce validation on the ajax_theme_activation function. This makes it possible for unauthenticated attackers to activate… | |
| Modificada | Media (4.3) | 0.27% | — | Envothemes Envo's Elementor Templates & Widgets FOR Woocommerce | 28/2/2024 | 17/6/2026 | The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on the ajax_plugin_activation function. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (4.3) | 0.46% | — | Envothemes Envo's Elementor Templates & Widgets FOR Woocommerce | 28/2/2024 | 17/6/2026 | The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the templates_ajax_request function in all versions up to, and including, 1.4.4. This makes it possible for subscribers and higher to create templates. | |
| Modificada | Alta (8.8) | 0.29% | — | Praveengoswami Advanced Category Template | 19/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Praveen Goswami Advanced Category Template.This issue affects Advanced Category Template: from n/a through 0.1. |