Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1033 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Mediaron Custom Query BlocksAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query Blocks: from n/a through <= 5.5.0. | |
| Aplazada | Media (5.3) | 0.33% | — | Posimyth Nexter BlocksAI | 8/4/2026 | 24/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Retrieve Embedded Sensitive Data.This issue affects Nexter Blocks: from n/a through <= 4.7.0. | |
| Aplazada | Media (6.5) | 0.47% | — | WP BlockadeAI | 8/4/2026 | 24/7/2026 | The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. The plugin registers an admin_post action hook 'wp-blockade-shortcode-render' that maps to the render_shortcode_preview() function. This function lacks any capability check (current_user_can()) and… | |
| Aplazada | Media (4.3) | 0.29% | — | Kadenceblocks Kadence BlocksAI | 4/4/2026 | 21/7/2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user has the `upload_files` capability in the `process_pattern` REST API endpoint. This makes it… | |
| Aplazada | Media (5.4) | 0.18% | — | Dogblocker Minify HtmlAI | 31/3/2026 | 25/7/2026 | The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. This makes it possible for unauthenticated attackers to update plugin settings via a forged… | |
| Aplazada | Crítica (9.9) | 0.52% | — | Crocoblock JetformbuilderAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1. | |
| Aplazada | Media (6.5) | 0.33% | — | Bplugins B BlocksAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Blocks: from n/a through < 2.0.30. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wpdive Nexa BlocksAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through <= 1.1.1. | |
| Aplazada | Crítica (9.9) | 0.45% | — | Simplygallery Simply Gallery BlockAI | 25/3/2026 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SimpLy Gallery: from n/a through <= 3.3.2. | |
| Aplazada | Alta (7.5) | 0.54% | — | Crocoblock JetengineAI | 24/3/2026 | 17/6/2026 | The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled input to bypass security checks)… | |
| Aplazada | Alta (7.5) | 0.57% | — | Crocoblock JetformbuilderAI | 21/3/2026 | 17/6/2026 | The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating that the path belongs… | |
| Aplazada | Media (6.4) | 0.24% | — | WpfaqblockAI | 21/3/2026 | 17/6/2026 | The WPFAQBlock– FAQ & Accordion Plugin For Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter of the 'wpfaqblock' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Alta (7.1) | 0.25% | — | Themehunk Gutenberg Blocks Unlimited-blocksAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks allows Reflected XSS.This issue affects Gutenberg Blocks: from n/a through <= 1.2.8. | |
| Aplazada | Media (4.3) | 0.34% | — | Wpzoom Social Icons Widget AND BlockAI | 13/3/2026 | 17/6/2026 | The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() method hooked to admin_menu in all versions up to, and including, 4.5.8. This is due to the method performing wp_insert_post() and update_post_meta()… | |
| Aplazada | Media (5.3) | 0.29% | — | Cyberchimps Responsive BlocksAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Blocks: from n/a through <= 2.2.0. | |
| Aplazada | Media (6.5) | 0.22% | — | Bplugins Icon List BlockAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block icon-list-block allows Stored XSS.This issue affects Icon List Block: from n/a through <= 1.2.3. | |
| Aplazada | Alta (8.8) | 0.52% | — | Crocoblock JetengineAI | 13/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1. | |
| Aplazada | Baja (2) | 0.51% | — | Mediawiki RenderblockingAI | 10/3/2026 | 17/6/2026 | RenderBlocking is a MediaWiki extension that allows interface administrators to specify render-blocking CSS and JavaScript. Prior to 0.1.1, there is Stored XSS in renderblocking-css with Inline Assets mode. $wgRenderBlockingInlineAssets = true and editsitecss user rights are required. This vulnerability is fixed in… | |
| Aplazada | Alta (8.5) | 0.40% | 💥 PoC | Crocoblock JetengineAI | 5/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue affects JetEngine: from n/a through <= 3.7.2. | |
| Aplazada | Media (6.4) | 0.27% | — | Creativethemes BlocksyAI | 2/3/2026 | 17/6/2026 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in all versions up to, and including, 2.1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Baja (1.1) | 0.24% | — | Chia Blockchain | 25/2/2026 | 17/6/2026 | A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Master Passphrase Handler. This manipulation causes missing authentication. The attack can only be executed locally. The attack's complexity is rated as high. The… | |
| Analizada | Baja (1.3) | 0.23% | — | Chia Blockchain | 25/2/2026 | 17/6/2026 | A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. The manipulation results in cross-site request forgery. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit… | |
| Analizada | Baja (2.9) | 0.90% | — | Chia Blockchain | 25/2/2026 | 17/6/2026 | A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of the component RPC Credential Handler. The manipulation leads to improper authentication. The attack is possible to be carried out remotely. The attack is considered to… | |
| Aplazada | Media (6.4) | 0.16% | — | Eaglevisionit Rise BlocksAI | 25/2/2026 | 17/6/2026 | The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘logoTag’ Site Identity block attribute in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.18% | — | Themebon Business Template Blocks FOR Wpbakery Page BuilderAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Business Template Blocks for WPBakery (Visual Composer) Page Builder templates-and-addons-for-wpbakery-page-builder allows Reflected XSS.This issue affects Business Template Blocks for WPBakery (Visual… |