Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetformbuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | |
| Aplazada | Media (6.1) | 0.21% | — | Crocoblock JetformbuilderAI | 25/9/2026 | 25/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.5) | 0.23% | — | Crocoblock JetformbuilderAI | 19/9/2026 | 21/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server… | |
| Aplazada | Crítica (9.8) | 0.52% | — | Crocoblock JetformbuilderAI | 16/9/2026 | 17/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and… | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetformbuilderAI | 8/9/2026 | 8/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions. | |
| Aplazada | Media (4.8) | 0.15% | — | Crocoblock JetformbuilderAI | 6/9/2026 | 8/9/2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender.… | |
| Aplazada | Media (6.5) | 0.20% | — | Crocoblock JetformbuilderAI | 6/9/2026 | 8/9/2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion… | |
| Aplazada | Media (4.7) | 0.17% | — | Crocoblock JetformbuilderAI | 5/9/2026 | 8/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other… | |
| Aplazada | Alta (7.5) | 0.32% | — | Jetformbuilder Dynamic Blocks Form BuilderAI | 5/9/2026 | 8/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft… | |
| Aplazada | Alta (7.5) | 0.35% | — | Crocoblock JetformbuilderAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. | |
| Aplazada | Media (5.3) | 0.58% | — | Crocoblock JetformbuilderAI | 2/7/2026 | 2/7/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve… | |
| Aplazada | Media (6.8) | 0.28% | — | Crocoblock JetformbuilderAI | 17/6/2026 | 16/9/2026 | Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affects JetFormBuilder: from n/a through 3.6.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetformbuilderAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions. | |
| Aplazada | Crítica (9.9) | 0.52% | — | Crocoblock JetformbuilderAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1. | |
| Aplazada | Alta (7.5) | 0.57% | — | Crocoblock JetformbuilderAI | 21/3/2026 | 17/6/2026 | The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating that the path belongs… | |
| Aplazada | Media (5.3) | 0.22% | — | Crocoblock JetformbuilderAI | 16/12/2025 | 17/6/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the run_callback function in all versions up to, and including, 3.5.3. This makes it possible for unauthenticated attackers to generate forms using AI, consuming… | |
| Aplazada | Media (5.3) | 0.26% | — | Crocoblock JetformbuilderAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetFormBuilder: from n/a through <= 3.5.3. | |
| Aplazada | Alta (7.2) | 0.47% | — | Crocoblock JetformbuilderAI | 16/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Object Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.1.2. | |
| Aplazada | Alta (7.2) | 0.53% | — | Crocoblock JetformbuilderAI | 3/8/2024 | 17/6/2026 | The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-level and above permissions, to register as super-admins on the… | |
| Aplazada | Alta (7.2) | 0.76% | — | Crocoblock JetformbuilderAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8. | |
| Aplazada | Media (5.3) | 0.37% | — | Crocoblock JetformbuilderAI | 24/4/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through 3.1.4. | |
| Modificada | Alta (8.8) | 0.26% | — | Crocoblock Jetformbuilder | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions. |