Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
1033 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Video Background BlockAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Crocoblock JetelementsAI | 6/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through 2.9.2.2. | |
| Aplazada | Alta (7.1) | 0.24% | — | Epiph Form BlockAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions. | |
| Aplazada | Media (6.9) | 0.27% | — | Cozythemes Cozy BlocksAI | 5/10/2026 | 6/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through 2.2.23. | |
| Aplazada | Media (6.5) | 0.16% | — | Bplugins B BlocksAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8. | |
| Aplazada | Alta (7.1) | 0.15% | — | Kadenceblocks Kadence BlocksAI | 4/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.11.1. | |
| Aplazada | Alta (7.2) | 0.24% | — | Crocoblock JetformbuilderAI | 2/10/2026 | 3/10/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Baja (3.1) | 0.29% | — | Themeisle Otter BlocksAI | 2/10/2026 | 3/10/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Alta (7.1) | 0.18% | — | Parallax Section BlockAI | 1/10/2026 | 1/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions. | |
| Aplazada | Media (6.4) | 0.29% | — | Wpdeveloper Essential BlocksAI | 1/10/2026 | 3/10/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map block's 'marker' attribute in versions up to, and including, 6.4.5 This is due to insufficient input sanitization and output escaping on marker… | |
| Aplazada | Alta (7.1) | 0.15% | — | Crocoblock JetformbuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Creativethemes Blocksy CompanionAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. | |
| Aplazada | Media (5.5) | 0.17% | — | Crocoblock JetengineAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Crocoblock JetengineAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | |
| Aplazada | Media (6.8) | 0.24% | — | Audio Player BlockAI | 30/9/2026 | 30/9/2026 | The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or… | |
| Pendiente de análisis | Media (6.1) | 0.30% | — | Netgate PfsenseAIPfblockerngAI | 25/9/2026 | 30/9/2026 | Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package | |
| Aplazada | Media (6.1) | 0.21% | — | Crocoblock JetformbuilderAI | 25/9/2026 | 25/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.3) | 0.27% | — | IXO BlockchainAI | 24/9/2026 | 30/9/2026 | The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved address belonged to the transaction signer. Affected handlers included… | |
| Aplazada | Media (6.5) | 0.17% | — | Premium BlocksAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Post Grid Gutenberg BlocksAI | 23/9/2026 | 23/9/2026 | The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending,… | |
| Aplazada | Alta (8.8) | 0.49% | — | Openwrt Luci-app-adblock-fastAI | 21/9/2026 | 29/9/2026 | luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as… | |
| Aplazada | Media (4.3) | 0.18% | — | BlockspareAI | 19/9/2026 | 21/9/2026 | The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (8.8) | 0.51% | — | Master BlocksAI | 19/9/2026 | 21/9/2026 | The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page. | |
| Aplazada | Media (5.5) | 0.23% | — | Crocoblock JetformbuilderAI | 19/9/2026 | 21/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server… | |
| Aplazada | Media (6.6) | 0.39% | — | Areoi ALL Bootstrap BlocksAI | 18/9/2026 | 18/9/2026 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file… |