Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2757▲ 47 respecto a la semana anterior
Críticas / altas1482▲ 372 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
495 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.13% | — | Visualcomposer Visual Composer Website BuilderAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions. | |
| Aplazada | Baja (2.1) | 0.28% | — | Coolbeans1212 Mateishomepage WebsiteAI | 29/9/2026 | 29/9/2026 | A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected by this issue is some unknown functionality of the file users.php. This manipulation of the argument Search causes cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Crítica (9.8) | 2.9% | — | Visualcomposer Visual Composer Website BuilderAI | 24/9/2026 | 24/9/2026 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP… | |
| Aplazada | Media (6.1) | 0.18% | — | KA Informatics Technologies LTD BAR Association WebsiteAI | 18/9/2026 | 18/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS. This issue affects Bar Association Website: through 18092026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Aplazada | Media (6.5) | 0.22% | — | Visualcomposer Website BuilderAI | 11/9/2026 | 11/9/2026 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions. | |
| Aplazada | Media (4.3) | 0.28% | — | Arma Digital Media INC Website TemplateAI | 11/9/2026 | 11/9/2026 | Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Media (5.3) | 0.33% | — | Dernekplus Website TemplateAI | 10/9/2026 | 10/9/2026 | Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Media (5.5) | 0.51% | — | Beijing Meite Software Technology U Smart Enjoyment WebsiteAI | 7/9/2026 | 8/9/2026 | A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack remotely.… | |
| Aplazada | Crítica (9.8) | 0.83% | — | AI Website BuilderAI | 4/9/2026 | 8/9/2026 | The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory,… | |
| Aplazada | Alta (7.5) | 0.84% | — | Maatwebsite Laravel ExcelAI | 1/9/2026 | 9/9/2026 | Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $export->store(), or storeExcel() against the process working directory… | |
| Aplazada | Media (6.9) | 0.41% | — | Extendthemes Kubio AI Website BuilderAI | 31/8/2026 | 8/9/2026 | Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1. | |
| Aplazada | Media (6.9) | 0.47% | — | Website NotificationsAI | 10/8/2026 | 26/8/2026 | The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transition addresses (NAT64 `64:ff9b::/96`, 6to4 `2002::/16`, Teredo `2001:0000::/32`) are classified as globally routable by IANA, so `is_global` returns `True` even when the… | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester Photo Share WebsiteAI | 7/8/2026 | 12/8/2026 | A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /social/ajax.php?action=save_upload of the component Comment Input Box. The manipulation of the argument content leads to cross site scripting. The attack may be initiated remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Photo Share WebsiteAI | 7/8/2026 | 12/8/2026 | A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.40% | — | Sourcecodester Photo Share WebsiteAI | 7/8/2026 | 12/8/2026 | A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=save_upload. Such manipulation of the argument img[]/imgName[] leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to… | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester Photo Share WebsiteAI | 7/8/2026 | 12/8/2026 | A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file /social/index.php?page=home. This manipulation of the argument Comment causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Photo Share WebsiteAI | 7/8/2026 | 12/8/2026 | A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=login. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Alta (8.6) | 1.0% | — | Websitebaker CMSAI | 3/8/2026 | 9/9/2026 | WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing a PHP webshell alongside a valid info.php metadata file. Attackers can place the… | |
| Aplazada | Alta (8.6) | 1.2% | — | Websitebaker CMSAI | 3/8/2026 | 9/9/2026 | WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization.… | |
| Aplazada | Media (6.1) | 0.25% | — | Polen Media Software AND Information Services Website TemplateAI | 24/7/2026 | 24/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2. | |
| Aplazada | Media (4.3) | 0.39% | — | GW AI Website BuilderAI | 10/7/2026 | 14/7/2026 | The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (6.4) | 0.26% | — | Seedprod Website BuilderAI | 8/7/2026 | 29/9/2026 | The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `seedprodnestedmenuwidget` shortcode in all versions up to, and including, 6.20.2 due to insufficient input sanitization and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Ecommerce WebsiteAI | 6/7/2026 | 6/7/2026 | A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Ecommerce WebsiteAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection. The attack can be executed remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Ecommerce WebsiteAI | 4/7/2026 | 7/7/2026 | A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… |