Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

1480 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)——Parallax Section BlockAI1/10/20261/10/2026
Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.
AplazadaMedia (6.4)——Wpdeveloper Essential BlocksAI1/10/20261/10/2026
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map block's 'marker' attribute in versions up to, and including, 6.4.5 This is due to insufficient input sanitization and output escaping on marker…
AplazadaAlta (7.1)0.25%—Crocoblock JetformbuilderAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
AplazadaMedia (6.5)0.27%—Creativethemes Blocksy CompanionAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.
AplazadaMedia (5.5)0.18%—Crocoblock JetengineAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
AplazadaMedia (6.8)0.24%—Audio Player BlockAI30/9/202630/9/2026
The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or…
Pendiente de análisisMedia (6.1)0.30%—Netgate PfsenseAIPfblockerngAI25/9/202630/9/2026
Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package
AplazadaMedia (6.1)0.21%—Crocoblock JetformbuilderAI25/9/202625/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaCrítica (9.3)0.27%—IXO BlockchainAI24/9/202630/9/2026
The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved address belonged to the transaction signer. Affected handlers included…
AplazadaMedia (6.5)0.17%—Premium BlocksAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.
AplazadaMedia (5.3)0.21%—Post Grid Gutenberg BlocksAI23/9/202623/9/2026
The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending,…
AplazadaAlta (8.8)0.49%—Openwrt Luci-app-adblock-fastAI21/9/202629/9/2026
luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as…
AplazadaMedia (4.3)0.18%—BlockspareAI19/9/202621/9/2026
The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes it possible for authenticated attackers, with Subscriber-level access…
AplazadaAlta (8.8)0.51%—Master BlocksAI19/9/202621/9/2026
The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.
AplazadaMedia (5.5)0.23%—Crocoblock JetformbuilderAI19/9/202621/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server…
AplazadaMedia (6.6)0.39%—Areoi ALL Bootstrap BlocksAI18/9/202618/9/2026
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file…
AplazadaMedia (4.3)0.42%—Themegrill Magazine BlocksAI18/9/202618/9/2026
The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.6. This is due to the plugin not properly verifying that a user is authorized to perform an action.…
AplazadaMedia (6.4)0.35%—Themegrill Magazine BlocksAI18/9/202618/9/2026
The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6. This is due to insufficient input sanitization and output escaping in the NewsTicker::render() method, which concatenates the clientId block…
AplazadaMedia (6.8)0.43%—Areoi ALL Bootstrap BlocksAI18/9/202618/9/2026
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
Pendiente de análisisMedia (5.3)0.45%—OmniblocksAI17/9/202623/9/2026
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was…
AplazadaMedia (6.5)0.22%—Motopress Jetblocks FOR ElementorAI17/9/202617/9/2026
Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
AplazadaMedia (6.5)0.22%—Crocoblock Jetelements FOR ElementorAI17/9/202619/9/2026
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.
AplazadaMedia (5.3)0.34%—Prestashop BlockwishlistAI16/9/202622/9/2026
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers'…
AplazadaCrítica (9.8)0.52%—Crocoblock JetformbuilderAI16/9/202617/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and…