Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
1480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | — | — | Parallax Section BlockAI | 1/10/2026 | 1/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions. | |
| Aplazada | Media (6.4) | — | — | Wpdeveloper Essential BlocksAI | 1/10/2026 | 1/10/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map block's 'marker' attribute in versions up to, and including, 6.4.5 This is due to insufficient input sanitization and output escaping on marker… | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetformbuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Creativethemes Blocksy CompanionAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. | |
| Aplazada | Media (5.5) | 0.18% | — | Crocoblock JetengineAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | |
| Aplazada | Media (6.8) | 0.24% | — | Audio Player BlockAI | 30/9/2026 | 30/9/2026 | The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or… | |
| Pendiente de análisis | Media (6.1) | 0.30% | — | Netgate PfsenseAIPfblockerngAI | 25/9/2026 | 30/9/2026 | Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package | |
| Aplazada | Media (6.1) | 0.21% | — | Crocoblock JetformbuilderAI | 25/9/2026 | 25/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.3) | 0.27% | — | IXO BlockchainAI | 24/9/2026 | 30/9/2026 | The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved address belonged to the transaction signer. Affected handlers included… | |
| Aplazada | Media (6.5) | 0.17% | — | Premium BlocksAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Post Grid Gutenberg BlocksAI | 23/9/2026 | 23/9/2026 | The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending,… | |
| Aplazada | Alta (8.8) | 0.49% | — | Openwrt Luci-app-adblock-fastAI | 21/9/2026 | 29/9/2026 | luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as… | |
| Aplazada | Media (4.3) | 0.18% | — | BlockspareAI | 19/9/2026 | 21/9/2026 | The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (8.8) | 0.51% | — | Master BlocksAI | 19/9/2026 | 21/9/2026 | The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page. | |
| Aplazada | Media (5.5) | 0.23% | — | Crocoblock JetformbuilderAI | 19/9/2026 | 21/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server… | |
| Aplazada | Media (6.6) | 0.39% | — | Areoi ALL Bootstrap BlocksAI | 18/9/2026 | 18/9/2026 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file… | |
| Aplazada | Media (4.3) | 0.42% | — | Themegrill Magazine BlocksAI | 18/9/2026 | 18/9/2026 | The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.6. This is due to the plugin not properly verifying that a user is authorized to perform an action.… | |
| Aplazada | Media (6.4) | 0.35% | — | Themegrill Magazine BlocksAI | 18/9/2026 | 18/9/2026 | The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6. This is due to insufficient input sanitization and output escaping in the NewsTicker::render() method, which concatenates the clientId block… | |
| Aplazada | Media (6.8) | 0.43% | — | Areoi ALL Bootstrap BlocksAI | 18/9/2026 | 18/9/2026 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed. | |
| Pendiente de análisis | Media (5.3) | 0.45% | — | OmniblocksAI | 17/9/2026 | 23/9/2026 | OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was… | |
| Aplazada | Media (6.5) | 0.22% | — | Motopress Jetblocks FOR ElementorAI | 17/9/2026 | 17/9/2026 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Crocoblock Jetelements FOR ElementorAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | |
| Aplazada | Media (5.3) | 0.34% | — | Prestashop BlockwishlistAI | 16/9/2026 | 22/9/2026 | PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers'… | |
| Aplazada | Crítica (9.8) | 0.52% | — | Crocoblock JetformbuilderAI | 16/9/2026 | 17/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and… |