Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 296 respecto a la semana anterior
Críticas / altas1350▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.19% | — | Spectra LegacyAI | 24/9/2026 | 24/9/2026 | The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option through the uagb_blocks_info object without a capability check. This makes it… | |
| Aplazada | Baja (3.5) | 0.15% | — | Spectra LegacyAI | 1/8/2026 | 26/8/2026 | The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the pages that render the affected block. The injected styles are… | |
| Aplazada | Media (6.4) | 0.32% | — | Spectra Gutenberg BlocksAI | 20/7/2026 | 22/7/2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (8.8) | 0.97% | — | Bracketspace SpectraAI | 30/5/2026 | 22/7/2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation… | |
| Aplazada | Media (4.3) | 0.27% | — | Brainstormforce SpectraAIBrainstormforce Ultimate-addons-for-gutenbergAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.22. | |
| Aplazada | Media (5.3) | 0.26% | — | Brainstormforce SpectraAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.17. | |
| Aplazada | Media (5.3) | 0.40% | — | Spectra Gutenberg BlocksAI | 3/2/2026 | 17/6/2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before rendering post excerpts in the `render_excerpt()` function and the… | |
| Aplazada | Media (5.4) | 0.25% | — | Brainstormforce SpectraAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0. | |
| Aplazada | Media (6.4) | 0.22% | — | Spectra Gutenberg BlocksAI | 5/11/2025 | 17/6/2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2.19.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.30% | — | SpectraAI | 26/3/2025 | 17/6/2026 | The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb block in all versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Modificada | Crítica (9.8) | 0.65% | — | Brainstormforce Spectra | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0. | |
| Modificada | Alta (8.8) | 0.55% | — | Brainstormforce Spectra | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0. | |
| Analizada | Media (5.4) | 0.30% | — | Brainstormforce Spectra | 3/12/2024 | 17/6/2026 | The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (8.8) | 0.43% | — | Brainstormforce Spectra | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.13.7. | |
| Aplazada | Crítica (9.3) | 0.51% | — | Ciena Ons-s8 Spectra Aggregation SwitchAI | 3/10/2024 | 17/6/2026 | The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication process, which can lead to an attacker authenticating without a password. | |
| Aplazada | Crítica (9.3) | 0.70% | — | Ciena Ons-s8 Spectra Aggregation SwitchAI | 3/10/2024 | 17/6/2026 | The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass authentication, and execute remote code. | |
| Modificada | Media (5.4) | 0.33% | — | Brainstormforce Spectra | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows DOM-Based XSS.This issue affects Spectra: from n/a through <= 2.14.1. | |
| Analizada | Media (5.4) | 0.28% | — | Wpspectra Spectra | 2/8/2024 | 17/6/2026 | The Spectra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block ids in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Modificada | Alta (8.8) | 0.46% | — | Brainstormforce Spectra | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6. | |
| Analizada | Media (5.3) | 0.33% | — | Brainstormforce Spectra | 3/6/2024 | 17/6/2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brainstorm Force Spectra allows Content Spoofing, Phishing.This issue affects Spectra: from n/a through 2.3.0. | |
| Analizada | Media (6.1) | 0.28% | — | Brainstormforce Spectra | 3/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brainstorm Force Spectra allows Code Injection.This issue affects Spectra: from n/a through 2.3.0. | |
| Analizada | Media (5.3) | 0.37% | — | Brainstormforce Spectra | 3/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality Bypass.This issue affects Spectra: from n/a through 2.3.0. | |
| Modificada | Media (5.4) | 0.26% | — | Brainstormforce Spectra | 24/5/2024 | 17/6/2026 | The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘block_id’ parameter in versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions… | |
| Modificada | Media (5.4) | 0.26% | — | Brainstormforce Spectra | 23/5/2024 | 17/6/2026 | The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.26% | — | Brainstormforce Spectra | 23/5/2024 | 17/6/2026 | The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… |