Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▲ 27 respecto a la semana anterior
Críticas / altas1477▲ 294 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
506 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.1) | 0.29% | — | Themeisle Otter BlocksAI | 2/10/2026 | 2/10/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Media (6.4) | 0.29% | — | Wpdeveloper Essential BlocksAI | 1/10/2026 | 1/10/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map block's 'marker' attribute in versions up to, and including, 6.4.5 This is due to insufficient input sanitization and output escaping on marker… | |
| Aplazada | Media (6.5) | 0.21% | — | Creativethemes Blocksy CompanionAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Premium BlocksAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Post Grid Gutenberg BlocksAI | 23/9/2026 | 23/9/2026 | The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending,… | |
| Aplazada | Media (4.3) | 0.18% | — | BlockspareAI | 19/9/2026 | 21/9/2026 | The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (8.8) | 0.51% | — | Master BlocksAI | 19/9/2026 | 21/9/2026 | The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page. | |
| Aplazada | Media (6.6) | 0.39% | — | Areoi ALL Bootstrap BlocksAI | 18/9/2026 | 18/9/2026 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file… | |
| Aplazada | Media (4.3) | 0.42% | — | Themegrill Magazine BlocksAI | 18/9/2026 | 18/9/2026 | The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.6. This is due to the plugin not properly verifying that a user is authorized to perform an action.… | |
| Aplazada | Media (6.4) | 0.35% | — | Themegrill Magazine BlocksAI | 18/9/2026 | 18/9/2026 | The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6. This is due to insufficient input sanitization and output escaping in the NewsTicker::render() method, which concatenates the clientId block… | |
| Aplazada | Media (6.8) | 0.43% | — | Areoi ALL Bootstrap BlocksAI | 18/9/2026 | 18/9/2026 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed. | |
| Pendiente de análisis | Media (5.3) | 0.45% | — | OmniblocksAI | 17/9/2026 | 23/9/2026 | OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was… | |
| Aplazada | Media (6.5) | 0.22% | — | Motopress Jetblocks FOR ElementorAI | 17/9/2026 | 17/9/2026 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | |
| Aplazada | Media (5.3) | 0.39% | — | Themeisle Otter BlocksAI | 7/9/2026 | 8/9/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the 'watch_checkout' function due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Pickplugins ComboblocksAI | 5/9/2026 | 8/9/2026 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress,… | |
| Aplazada | Alta (7.5) | 0.32% | — | Jetformbuilder Dynamic Blocks Form BuilderAI | 5/9/2026 | 8/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft… | |
| Aplazada | Media (6.5) | 0.22% | — | Gallery PhotoblocksAI | 2/9/2026 | 3/9/2026 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Creativethemes Blocksy CompanionAI | 1/9/2026 | 1/9/2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and including, 2.1.51 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level… | |
| Aplazada | Media (5.3) | 0.39% | — | Cozythemes Cozy BlocksAI | 1/9/2026 | 1/9/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Alta (7.1) | 0.60% | — | Powsybl Power System BlocksAI | 28/8/2026 | 9/9/2026 | PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and environment variables into strings interpreted through bash -c or cmd /c without sufficient escaping. Attacker-controlled… | |
| Aplazada | Crítica (9.8) | 2.9% | — | 23blocks-os Ai-maestroAI | 28/8/2026 | 9/9/2026 | An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input. | |
| Aplazada | Media (6.4) | 0.36% | — | Greenshift Animation AND Page Builder BlocksAI | 26/8/2026 | 26/8/2026 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up to, and including, 12.8.9. This is due to insufficient sanitization of API responses before output via innerHTML. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.35% | — | Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI | 26/8/2026 | 26/8/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.35% | — | Cozythemes Cozy BlocksAI | 25/8/2026 | 26/8/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cozyHoverEffect Block Attribute in all versions up to, and including, 2.2.16 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Alta (7.1) | 0.25% | — | Renzojohnson BlocksAI | 24/8/2026 | 26/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. |