Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | — | — | Divi MembershipAI | 2/10/2026 | 2/10/2026 | The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash… | |
| Aplazada | Crítica (9.8) | 0.40% | — | Divi MembershipAI | 2/10/2026 | 2/10/2026 | The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership… | |
| Aplazada | Alta (8.2) | 0.26% | — | Divi DashAI | 23/9/2026 | 23/9/2026 | The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound,… | |
| Aplazada | Media (6.5) | 0.22% | — | Divi EssentialAI | 19/9/2026 | 21/9/2026 | The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_database_tables and dnxte_get_database_data AJAX actions. The handlers only conditionally verify a nonce (the check runs solely when the 'nonce' POST parameter is present… | |
| Aplazada | Media (5.3) | 0.45% | — | Elegantthemes DiviAI | 18/9/2026 | 18/9/2026 | The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5) | 0.36% | — | Elegantthemes DiviAI | 5/9/2026 | 8/9/2026 | The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get()` to fetch a remote image URL, which does not restrict requests to… | |
| Aplazada | Media (6.4) | 0.26% | — | Elegantthemes DiviAI | 5/9/2026 | 8/9/2026 | The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, and including, 4.27.6. This is due to the `image_src` field not being included in the `$url_options` whitelist (which only contains `url`,… | |
| Aplazada | Crítica (9.8) | 0.59% | — | Divi Ajax FilterAI | 4/9/2026 | 7/9/2026 | The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any… | |
| Aplazada | Media (6.4) | 0.26% | — | Elegantthemes DiviAI | 3/9/2026 | 3/9/2026 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, and including, 4.27.6. This is due to a three-part sanitization failure: (1) the `skype_url` field is not included in the `$url_options` whitelist… | |
| Aplazada | Media (6.4) | 0.26% | — | Elegantthemes DiviAI | 2/9/2026 | 4/9/2026 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is due to the `redirect_url` attribute being sanitized with `esc_attr()` instead of `esc_url()` before being rendered into… | |
| Aplazada | Media (6.4) | 0.28% | — | Elegantthemes DiviAI | 2/9/2026 | 3/9/2026 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter `et_builder_sanitize_dynamic_content_fields()` only searches for… | |
| Aplazada | Media (6.8) | 0.23% | — | Sogo ADD Script TO Individual Pages Header FooterAI | 30/8/2026 | 31/8/2026 | The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store… | |
| Aplazada | Media (5.4) | 0.23% | — | Elegantthemes DiviAI | 16/8/2026 | 26/8/2026 | The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post. | |
| Aplazada | Alta (8.8) | 0.29% | — | Divi Torque LiteAI | 9/7/2026 | 9/7/2026 | The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of '__return_true' as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which… | |
| Aplazada | Alta (8.8) | 0.44% | — | Elegantthemes Divi Form BuilderAI | 9/7/2026 | 9/7/2026 | The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and… | |
| Aplazada | Crítica (9.8) | 3.5% | — | Divi Form BuilderAI | 2/7/2026 | 2/7/2026 | The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is… | |
| Aplazada | Alta (8.6) | 0.64% | — | Contact Form Extender FOR DiviAI | 15/6/2026 | 17/6/2026 | Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field <= 1.0.6 versions. | |
| Aplazada | Alta (8.8) | 0.71% | — | Content Visibility FOR Divi BuilderAI | 2/6/2026 | 22/7/2026 | The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (6.4) | 0.33% | — | Simple Divi ShortcodeAI | 29/5/2026 | 21/7/2026 | The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, and including, 1.2 This is due to insufficient input sanitization and output escaping in the showmodule_shortcode() function, which concatenates the 'id'… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Divi Form BuilderAI | 21/5/2026 | 23/7/2026 | The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This… | |
| Aplazada | Baja (1.9) | 0.15% | — | Noelse Individuals & PRO APPAI | 3/4/2026 | 24/7/2026 | A weakness has been identified in Noelse Individuals & Pro App up to 2.1.7 on Android. This impacts an unknown function of the file com/reactnative/antelop/BuildConfig.java of the component com.afone.noelse. This manipulation of the argument SEGMENT_WRITE_KEY causes use of hard-coded cryptographic key . The attack… | |
| Aplazada | Baja (2) | 0.33% | — | Campcodes Division Regional Athletic Meet Game Result Matrix SystemAI | 12/3/2026 | 17/6/2026 | A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This vulnerability affects unknown code of the file save_up_athlete.php. This manipulation of the argument a_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Baja (2) | 0.33% | — | Campcodes Division Regional Athletic Meet Game Result Matrix SystemAI | 12/3/2026 | 17/6/2026 | A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This affects an unknown part of the file save-games.php. The manipulation of the argument game_name results in cross site scripting. The attack may be performed from remote. The exploit has been released to… | |
| Aplazada | Alta (8.1) | 0.22% | — | Divi BoosterAI | 11/3/2026 | 17/6/2026 | The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin before 5.0.2 options. Furthermore, due to the use of unserialize() on the data, this could be further exploited when… | |
| Aplazada | Alta (7.6) | 0.21% | — | Kod8 Software Technologies Trade Kod8 Individual AND SME WebsiteAI | 3/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kod8 Software Technologies Trade Ltd. Co. Kod8 Individual and SME Website allows Reflected XSS. This issue affects Kod8 Individual and SME Website: through 03022026. NOTE: The vendor was contacted early about… |