Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.21%—Creativethemes Blocksy CompanionAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.
AplazadaMedia (6.4)0.33%—Creativethemes Blocksy CompanionAI1/9/20261/9/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and including, 2.1.51 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level…
AplazadaCrítica (9.8)1.1%—Creativethemes Blocksy CompanionAI9/7/20269/7/2026
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring…
AplazadaCrítica (9.2)3.6%—Blocksy Companion PROAI8/7/20268/7/2026
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom…
AplazadaMedia (5.3)0.31%—Blocksy Companion PROAI26/6/202626/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.
AplazadaAlta (8.5)0.58%—Blocksy Companion PROAI26/6/202626/6/2026
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.
AplazadaMedia (4.4)0.34%—Creativethemes Blocksy CompanionAI19/6/202622/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject…
AplazadaCrítica (9.9)0.79%—Blocksy Companion PROAI17/6/202617/6/2026
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.
AplazadaCrítica (9.3)0.40%—Blocksy Companion PROAI17/6/202617/6/2026
Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.
AplazadaAlta (8.8)0.69%—Creativethemes Blocksy CompanionAI11/11/202517/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to insufficient file type validation detecting SVG files, allowing double extension files to bypass sanitization while being accepted as a valid SVG file. This makes…
AplazadaMedia (6.4)0.20%—Creativethemes Blocksy CompanionAI30/10/202517/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsletter_subscribe' shortcode in all versions up to, and including, 2.1.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (6.4)0.25%—Creativethemes Blocksy CompanionAI17/9/202517/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newsletter_subscribe shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
ModificadaMedia (4.9)0.26%—Creativethemes Blocksy Companion3/6/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Creative Themes Blocksy Companion blocksy-companion.This issue affects Blocksy Companion: from n/a through <= 2.0.42.
ModificadaMedia (5.4)0.43%—Creativethemes Blocksy Companion14/5/202417/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject…
ModificadaAlta (8.8)0.21%—Creativethemes Blocksy Companion11/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy Companion.This issue affects Blocksy Companion: from n/a through 2.0.28.
ModificadaMedia (5.4)0.34%—Creativethemes Blocksy Companion22/3/202417/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaMedia (4.3)0.55%—Creativethemes Blocksy Companion2/5/202317/6/2026
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example
ModificadaMedia (5.4)0.34%—Creativethemes Blocksy Companion6/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions.