Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.21% | — | Cozmoslabs Profile BuilderAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions. | |
| Aplazada | Alta (7.2) | 0.26% | — | User Profile BuilderAI | 25/9/2026 | 25/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.20% | — | Codeselling User Profile BuilderAI | 25/9/2026 | 25/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.42% | — | Codesigner User Profile BuilderAI | 7/9/2026 | 9/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (6.1) | 0.38% | — | Codesmiths User Profile BuilderAI | 1/9/2026 | 1/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.33% | — | Codesigner User Profile BuilderAI | 1/9/2026 | 1/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (5.5) | 0.50% | — | Cozmoslabs Profile BuilderAI | 31/8/2026 | 31/8/2026 | A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is… | |
| Aplazada | Alta (8.2) | 0.32% | — | Codesmiths User Profile BuilderAI | 29/8/2026 | 31/8/2026 | The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other… | |
| Aplazada | Media (6.6) | 0.42% | — | Cozmoslabs User Profile BuilderAI | 29/8/2026 | 31/8/2026 | The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is… | |
| Aplazada | Media (6.8) | 0.43% | — | User Profile BuilderAI | 29/8/2026 | 31/8/2026 | The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by… | |
| Aplazada | Crítica (9.8) | 3.9% | — | User Profile BuilderAI | 15/8/2026 | 20/8/2026 | The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is… | |
| Aplazada | Media (5.3) | 0.29% | — | Cozmoslabs Profile BuilderAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. | |
| Aplazada | Alta (8.1) | 0.38% | — | Codesmiths User Profile BuilderAI | 1/8/2026 | 26/8/2026 | The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported… | |
| Aplazada | Alta (7.1) | 0.25% | — | Profile Builder PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions. | |
| Aplazada | Alta (8.1) | 0.62% | — | Profile Builder PROAI | 2/5/2026 | 17/6/2026 | The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the wppb_request_users_pins_action_callback() AJAX handler, which lacked… | |
| Aplazada | Media (4.3) | 0.26% | — | Cozmoslabs User Profile BuilderAI | 31/3/2026 | 25/7/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on a user controlled key. This makes it… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Cozmoslabs Profile Builder PROAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0. | |
| Aplazada | Crítica (9.8) | 0.54% | — | User Profile BuilderAI | 2/2/2026 | 17/6/2026 | The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account | |
| Aplazada | Media (6.4) | 0.18% | — | Coatedmedia User Profile BuilderAI | 19/11/2025 | 17/6/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Media (6.4) | 0.20% | — | Codesigner User Profile BuilderAI | 16/8/2025 | 17/6/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping.… | |
| Aplazada | Media (4.3) | 0.31% | — | Cozmoslabs Profile BuilderAI | 6/6/2025 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder profile-builder allows Phishing.This issue affects Profile Builder: from n/a through <= 3.13.8. | |
| Aplazada | Media (6.4) | 0.28% | — | Cozmoslabs Profile BuilderAI | 3/6/2025 | 17/6/2026 | The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (4.8) | 0.34% | — | Cozmoslabs Profile Builder | 15/5/2025 | 17/6/2026 | The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks. | |
| Aplazada | Media (6.4) | 0.31% | — | Codespress User Profile BuilderAI | 16/4/2025 | 17/6/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Media (6.1) | 0.39% | — | Codesmiths Interactive User Profile BuilderAI | 7/1/2025 | 17/6/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user meta parameters in all versions up to, and including, 3.12.9 due to insufficient input sanitization and output escaping. This makes it… |