Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.25% | — | Starter TemplatesAI | 11/9/2026 | 11/9/2026 | Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. | |
| Aplazada | Alta (7.5) | 0.46% | — | Kadencewp Starter TemplatesAI | 18/8/2026 | 20/8/2026 | Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. | |
| Aplazada | Alta (8.8) | 14% | — | Starter TemplatesAI | 6/12/2025 | 17/6/2026 | The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible… | |
| Analizada | Crítica (9.1) | 0.43% | — | Fancywp Starter Templates | 8/3/2025 | 17/6/2026 | The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 via the 'http_request_host_is_external' filter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web… | |
| Aplazada | Crítica (9.6) | 0.24% | — | Fancywp Starter TemplatesAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP starter-templates allows Cross Site Request Forgery.This issue affects Starter Templates by FancyWP: from n/a through <= 2.0.0. | |
| Aplazada | Media (5.9) | 0.27% | — | Brainstormforce Starter TemplatesAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through <= 4.4.0. | |
| Modificada | Media (6.5) | 0.40% | — | Brainstormforce Starter Templates | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Premium Starter Templates, Brainstorm Force Starter Templates astra-sites.This issue affects Premium Starter Templates: from n/a through 3.2.5; Starter Templates: from n/a through 3.2.5. | |
| Aplazada | Media (6.4) | 0.45% | — | Starter TemplatesAI | 14/5/2024 | 17/6/2026 | The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.57% | — | Starter TemplatesAI | 14/5/2024 | 17/6/2026 | The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attackers, with contributor-level access and above, to make web… | |
| Aplazada | Alta (7.1) | 0.32% | — | Brainstormforce Starter Templates Elementor Wordpress Beaver Builder TemplatesAIBrainstormforce Premium Starter TemplatesAI | 28/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates, Brainstorm Force Premium Starter Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4; Premium Starter Templates:… | |
| Modificada | Media (5.4) | 0.40% | — | Brainstormforce Starter Templates | 7/12/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4. | |
| Modificada | Alta (8.8) | 0.26% | — | Brainstormforce Starter Templates | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions. | |
| Modificada | Alta (8.8) | 0.92% | — | Kadencewp Starter Templates | 9/1/2023 | 17/6/2026 | The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | |
| Modificada | Media (5.4) | 0.60% | — | Brainstormforce Starter Templates | 17/11/2021 | 17/6/2026 | On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious… |