Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
9631 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.1) | 0.53% | — | Fastlinemedia Beaver BuilderAI | 3/10/2026 | 3/10/2026 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.… | |
| Recibida | Alta (8.8) | 0.17% | — | Kubio AI Page BuilderAI | 3/10/2026 | 3/10/2026 | The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before… | |
| Recibida | Media (6.8) | 0.15% | — | Kubio AI Page BuilderAI | 3/10/2026 | 3/10/2026 | The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator… | |
| Recibida | Media (6.1) | 0.31% | — | Wpclever WPC Smart Quick ViewAI | 3/10/2026 | 3/10/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-redirect' parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Recibida | Media (6.5) | 0.27% | — | Fastlinemedia Beaver BuilderAI | 3/10/2026 | 3/10/2026 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Alta (7.2) | 0.24% | — | Crocoblock JetformbuilderAI | 2/10/2026 | 3/10/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.2) | 0.31% | — | Kubio AI Page BuilderAI | 2/10/2026 | 3/10/2026 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (4.3) | 0.18% | — | Inspireui Mstore APIAI | 2/10/2026 | 2/10/2026 | The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying. | |
| Aplazada | Media (6.2) | 0.21% | — | Mobyproject BuildkitAI | 2/10/2026 | 2/10/2026 | The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated… | |
| Aplazada | Alta (8.3) | 0.31% | — | Eclipse Basyx AAS WEB UIAI | 1/10/2026 | 1/10/2026 | In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted… | |
| Aplazada | Alta (8.5) | 0.21% | — | Villatheme WOO Product BuilderAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Alta (8.7) | 0.23% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Crítica (9.3) | 0.27% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Alta (8.7) | 0.18% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation. This issue affects… | |
| Aplazada | Crítica (9.3) | 0.38% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Alta (7.2) | 0.30% | — | Siteorigin Page BuilderAI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Crocoblock JetformbuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Boldgrid Post AND Page BuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | |
| Aplazada | Media (6.5) | 0.13% | — | Visualcomposer Visual Composer Website BuilderAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions. | |
| Aplazada | Alta (8.8) | 0.36% | — | Themify BuilderAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Cozmoslabs Profile BuilderAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions. | |
| Aplazada | Alta (7.6) | 0.28% | — | Quiz CATAI | 30/9/2026 | 30/9/2026 | Author SQL Injection in Quiz Cat <= 3.1.1 versions. |