Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 5/10/2026 | 6/10/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Parameter Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Aplazada | Crítica (9.3) | 0.25% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 4/10/2026 | 6/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Aplazada | Alta (7.1) | 0.15% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 4/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,… | |
| Aplazada | Alta (7.1) | 0.15% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,… | |
| Aplazada | Media (6.3) | 0.18% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level… | |
| Aplazada | Media (6.8) | 0.22% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and to retrieve non-public content, when a related widget option is set away from its default. | |
| Aplazada | Media (6.6) | 0.42% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress… | |
| Aplazada | Media (5.4) | 0.18% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 2/10/2026 | 2/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level… | |
| Aplazada | Media (6.8) | 0.24% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 2/10/2026 | 2/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered. | |
| Aplazada | Media (5.3) | 0.19% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates):… | |
| Aplazada | Alta (8.5) | 0.21% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Aplazada | Alta (7.5) | 0.40% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 20/9/2026 | 21/9/2026 | The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the… | |
| Aplazada | Media (6.4) | 0.23% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 17/9/2026 | 17/9/2026 | Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions. | |
| Aplazada | Media (6.1) | 0.45% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 11/9/2026 | 11/9/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.5) | 0.33% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 11/9/2026 | 11/9/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString()… | |
| Aplazada | Alta (7.1) | 0.25% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 8/9/2026 | 8/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions. | |
| Aplazada | Media (6.1) | 0.38% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 5/9/2026 | 8/9/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including, 2.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.31% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/9/2026 | 3/9/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17. | |
| Aplazada | Media (6.4) | 0.26% | — | ALL IN ONE WP Migration Unlimited ExtensionAI | 28/8/2026 | 28/8/2026 | The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ai1wm_backups_path' parameter in all versions up to, and including, 2.84. This is due to insufficient input sanitization and output escaping on user-supplied attributes combined with missing… | |
| Aplazada | Media (6.5) | 0.44% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 6/8/2026 | 12/8/2026 | Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/8/2026 | 12/8/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15. | |
| Aplazada | Alta (8.8) | 0.51% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 20/7/2026 | 21/7/2026 | The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver… | |
| Aplazada | Alta (7.1) | 0.25% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 17/6/2026 | 17/6/2026 | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Live Chat UnlimitedAI | 4/6/2026 | 22/7/2026 | Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area, enabling cookie theft or forced… |