Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
1426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.25% | — | Bricks BuilderAI | 17/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | TaskbuilderAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Funnelkit Funnel BuilderAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Funnelkit Funnel BuilderAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions. | |
| Aplazada | Crítica (10) | 0.56% | — | Rednao Woocommerce PDF Invoice BuilderAI | 15/6/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8. | |
| Aplazada | Media (5.4) | 0.27% | — | Codepeople Form Builder CPAI | 15/6/2026 | 21/7/2026 | The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page… | |
| Analizada | Media (5.9) | 0.31% | — | Nuxt/rspack-builderNuxt/webpack-builder | 12/6/2026 | 17/6/2026 | Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when using the webpack / rspack builder if the… | |
| Analizada | Media (5.9) | 0.37% | — | Nuxt/rspack-builderNuxt/webpack-builder | 12/6/2026 | 17/6/2026 | Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions 3.15.4 to before 3.21.6, and 4.0.0-alpha.1 to before 4.4.6, there is an incomplete fix for GHSA-4gf7-ff8x-hq99. Source code may be stolen during dev when using the webpack / rspack builder if the dev… | |
| Aplazada | Media (5.4) | 0.18% | — | Themehunk Contact Form AND Lead Form Elementor BuilderAI | 11/6/2026 | 26/9/2026 | Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Contact Form & Lead Form Elementor Builder: from n/a through 1.8.4. | |
| Aplazada | Baja (3.5) | 0.24% | — | Custom Block BuilderAI | 9/6/2026 | 23/7/2026 | The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary… | |
| Aplazada | Media (5.1) | 0.17% | — | Wordpress Popup BuilderAI | 4/6/2026 | 22/7/2026 | WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads in the post_title… | |
| Aplazada | Alta (8.8) | 0.71% | — | Content Visibility FOR Divi BuilderAI | 2/6/2026 | 22/7/2026 | The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (5.5) | 0.40% | — | Nextlevelbuilder GoclawAI | 2/6/2026 | 22/7/2026 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/auth.go of the component Webhook Verification Handler. The manipulation leads to missing authentication. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Baja (2.1) | 0.21% | — | Nextlevelbuilder GoclawAI | 2/6/2026 | 22/7/2026 | A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTool.executeComplete of the file internal/tools/team_tasks_lifecycle.go of the component Team Task Completion Handler. Executing a manipulation can lead to missing authorization. The attack may be… | |
| Aplazada | Baja (2) | 0.23% | — | Nextlevelbuilder GoclawAI | 2/6/2026 | 22/7/2026 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of the component TTS Configuration Endpoint. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.5) | 1.3% | — | Nextlevelbuilder GoclawAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.23% | — | Nextlevelbuilder GoclawAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.go. Such manipulation leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The project… | |
| Aplazada | Baja (2.1) | 0.21% | — | Nextlevelbuilder GoclawAI | 1/6/2026 | 22/7/2026 | A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.go of the component RoleAdmin Gateway. This manipulation causes improper privilege management. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Alta (7.3) | 0.51% | 💥 PoC | Falco Solutions PhppagebuilderAI | 29/5/2026 | 21/7/2026 | Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote code execution. The vulnerability exists due to insufficient validation of uploaded file types and executable content. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Whitestudio Easy Form BuilderAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder: from n/a through <= 4.0.6. | |
| Aplazada | Media (6.4) | 0.30% | — | Livemesh Addons FOR Beaver BuilderAI | 27/5/2026 | 17/6/2026 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user… | |
| Aplazada | Media (6.4) | 0.30% | — | Livemesh Wpbakery Page Builder AddonsAI | 27/5/2026 | 17/6/2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check… | |
| Aplazada | Media (6.4) | 0.24% | — | Livemesh Wpbakery Page Builder AddonsAI | 27/5/2026 | 17/6/2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[lvca_carousel]` and `[lvca_posts_carousel]` shortcode attributes in all versions up to, and including, 3.9.4 due to insufficient input sanitization and output escaping. Specifically, shortcode… | |
| Aplazada | Alta (7.1) | 0.21% | — | Wordpress Ultimate Form Builder LiteAI | 23/5/2026 | 23/7/2026 | WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter. Attackers can send POST requests to the admin-ajax.php endpoint with the… | |
| Aplazada | Crítica (9.8) | 0.53% | 💥 PoC | Divi Form BuilderAI | 21/5/2026 | 23/7/2026 | The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This… |