Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.46% | — | Ninjaforms Ninja Forms - Layout & StylesAI | 2/9/2026 | 3/9/2026 | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | |
| Aplazada | Media (6.5) | 0.47% | — | Layouts FOR WpbakeryAI | 5/8/2026 | 12/8/2026 | The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync()` callback registered via `wp_ajax_nopriv_handle_sync` in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.3) | 0.42% | — | Antv LayoutAI | 13/7/2026 | 14/7/2026 | A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/object.js. Executing a manipulation of the argument path can lead to improperly controlled modification of object prototype attributes. The attack can be launched remotely. The project was informed of… | |
| Aplazada | Alta (8.1) | 0.44% | — | Presslayouts PressmartAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions. | |
| Analizada | Alta (8.6) | 0.24% | — | Sound4 Playout Ula8 FirmwareSound4 Stream X8 FirmwareSound4 Stream X4 FirmwareSound4 Stream X2 Firmware+11 | 22/12/2025 | 17/6/2026 | SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem… | |
| Aplazada | Media (4.3) | 0.22% | — | Codeamp Custom Layouts Post Product Grids Made EasyAI | 9/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Code Amp Custom Layouts – Post + Product grids made easy custom-layouts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Layouts – Post + Product grids made easy: from n/a through <= 1.4.12. | |
| Aplazada | Media (6.5) | 0.20% | — | ACF Flexible Layouts ManagerAI | 18/11/2025 | 17/6/2026 | The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'acf_flm_update_template_with_pasted_layout' function in all versions up to, and including, 1.1.6. This makes it possible for unauthenticated attackers to update custom… | |
| Aplazada | Media (5.9) | 0.22% | — | Bestweblayout PortfolioAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bestweblayout Portfolio portfolio allows DOM-Based XSS.This issue affects Portfolio : from n/a through <= 2.58. | |
| Analizada | Media (4.3) | 0.24% | — | Layout Builder Advanced Permissions Project Layout Builder Advanced Permissions | 15/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue affects Layout Builder Advanced Permissions: from 0.0.0 before 2.2.0. | |
| Aplazada | Media (4.3) | 0.16% | — | Giraphix Creative Layouts FOR ElementorAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Giraphix Creative Layouts for Elementor layouts-for-elementor allows Cross Site Request Forgery.This issue affects Layouts for Elementor: from n/a through <= 1.11. | |
| Aplazada | Alta (7.3) | 0.52% | — | LayoutboxxAI | 6/5/2025 | 17/6/2026 | The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.3.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.6) | 0.34% | — | Bestweblayout Slider BY BestwebsoftAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bestweblayout Slider by BestWebSoft slider-bws allows SQL Injection.This issue affects Slider by BestWebSoft: from n/a through <= 1.1.0. | |
| Analizada | Crítica (9.8) | 0.55% | — | Presslayouts Pressmart | 18/2/2025 | 17/6/2026 | The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.16. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes… | |
| Aplazada | Media (5.4) | 0.30% | — | Shinetheme Traveler Layout Essential FOR ElementorAI | 3/2/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in shinetheme Traveler Layout Essential For Elementor traveler-layout-essential-for-elementor.This issue affects Traveler Layout Essential For Elementor: from n/a through < 1.4. | |
| Aplazada | Media (6.4) | 0.34% | — | Guten Post LayoutAI | 1/10/2024 | 17/6/2026 | The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:guten-post-layout/post-grid' Gutenberg block in all versions up to, and including, 1.2.4 due to insufficient input sanitization and… | |
| Aplazada | Media (6.5) | 0.25% | — | Codeamp Custom Layouts Post Product Grids Made EasyAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Code Amp Custom Layouts – Post + Product grids made easy allows Stored XSS.This issue affects Custom Layouts – Post + Product grids made easy: from n/a through 1.4.11. | |
| Aplazada | Media (6.5) | 0.32% | — | Techeshta Post Layouts FOR GutenbergAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Techeshta Post Layouts for Gutenberg allows Stored XSS.This issue affects Post Layouts for Gutenberg: from n/a through 1.2.7. | |
| Modificada | Alta (8.8) | 0.82% | — | Codevibrant WP Blog Post Layouts | 21/6/2024 | 17/6/2026 | The WP Blog Post Layouts plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code… | |
| Aplazada | Alta (7.5) | 0.46% | — | Techeshta Layouts FOR ElementorAI | 31/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Techeshta Layouts for Elementor.This issue affects Layouts for Elementor: from n/a before 1.8. | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens Xpedition Layout Browser | 10/10/2023 | 17/6/2026 | A vulnerability has been identified in Xpedition Layout Browser (All versions < VX.2.14). Affected application contains a stack overflow vulnerability when parsing a PCB file. An attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Crítica (9.8) | 1.0% | — | Jmsthemelayout Project Jmsthemelayout | 5/6/2023 | 17/6/2026 | PrestaShop jmsthemelayout 2.5.5 is vulnerable to SQL Injection via ajax_jmsvermegamenu.php. | |
| Modificada | Media (5.4) | 0.47% | — | Eaglevisionit Evision Responsive Column Layout Shortcodes | 6/3/2023 | 17/6/2026 | The eVision Responsive Column Layout Shortcodes WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.5) | 1.7% | — | Finn Podium LayoutFinn Podium Proxy | 6/4/2022 | 17/6/2026 | Podium is a library for building micro frontends. @podium/layout is a module for building a Podium layout server, and @podium/proxy is a module for proxying HTTP requests from a layout server to a podlet server. In @podium/layout prior to version 4.6.110 and @podium/proxy prior to version 4.2.74, an attacker using the… | |
| Modificada | Alta (7.5) | 1.4% | — | Glsl-layout Project Glsl-layout | 26/1/2021 | 17/6/2026 | An issue was discovered in the glsl-layout crate before 0.4.0 for Rust. When a panic occurs, map_array can perform a double drop. | |
| Modificada | Crítica (9.8) | 12% | — | Mobileviewpoint Wireless Multiplex Terminal Playout Server | 14/12/2020 | 17/6/2026 | The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon." |