Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

1417 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)——Villatheme WOO Product BuilderAI1/10/20261/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a…
AplazadaAlta (7.2)0.54%—Siteorigin Page BuilderAI30/9/202630/9/2026
Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetformbuilderAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
AplazadaAlta (7.1)0.25%—Boldgrid Post AND Page BuilderAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
AplazadaMedia (6.5)0.22%—Visualcomposer Visual Composer Website BuilderAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions.
AplazadaAlta (8.8)0.52%—Themify BuilderAI30/9/202630/9/2026
Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.
AplazadaMedia (6.5)0.22%—Cozmoslabs Profile BuilderAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible…
AplazadaAlta (7.2)0.26%—User Profile BuilderAI25/9/202625/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.2)0.27%—Themify BuilderAI25/9/202625/9/2026
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaMedia (6.4)0.20%—Codeselling User Profile BuilderAI25/9/202625/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.1)0.21%—Crocoblock JetformbuilderAI25/9/202625/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaCrítica (9.8)2.9%—Visualcomposer Visual Composer Website BuilderAI24/9/202624/9/2026
The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP…
AplazadaAlta (8.6)0.27%—Jet-form-builder-stripe-gatewayAI23/9/202623/9/2026
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.
AplazadaCrítica (9.8)0.66%—Ph7software Ph7builderAI22/9/202623/9/2026
pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the admin login attempt counter and lockout are keyed on this…
AplazadaMedia (6.5)0.50%—Ph7software Ph7builderAI22/9/202623/9/2026
Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form element is only built when that flag is present, so a remote…
AplazadaAlta (7.1)0.56%—Wptablebuilder WP Table BuilderAI22/9/202622/9/2026
The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.2.1. This is due to an operator precedence bug in the post-type guard within the trash_table_bulk() and restore_table_bulk() functions that causes the guard to never…
AplazadaAlta (8.8)0.57%—BM Content BuilderAI22/9/202622/9/2026
The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding, 3.17.1. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaMedia (6.5)0.53%—BM Content BuilderAI22/9/202622/9/2026
The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the…
AplazadaMedia (4.3)0.21%—PDF Builder FOR WoocommerceAI19/9/202621/9/2026
The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…
AplazadaMedia (5.5)0.23%—Crocoblock JetformbuilderAI19/9/202621/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server…