Creativethemes
Creativethemes Blocksy Companion: vulnerabilidades y CVE
Creativethemes Blocksy Companion tiene 13 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-97247 | Media (6.5) | 0.21% | — | 30 sept 2026 | Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. |
| CVE-2026-18488 | Media (6.4) | 0.33% | — | 1 sept 2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and including, 2.1.51 due to insufficient input… |
| CVE-2026-15158 | Crítica (9.8) | 1.1% | — | 9 jul 2026 | The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a… |
| CVE-2026-12430 | Media (4.4) | 0.34% | — | 19 jun 2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.45 due to insufficient input sanitization and output escaping. This… |
| CVE-2025-12846 | Alta (8.8) | 0.69% | — | 11 nov 2025 | The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to insufficient file type validation detecting SVG files,… |
| CVE-2025-12475 | Media (6.4) | 0.20% | — | 30 oct 2025 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsletter_subscribe' shortcode in all versions up to, and including, 2.1.14 due to insufficient input… |
| CVE-2025-9565 | Media (6.4) | 0.25% | — | 17 sept 2025 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newsletter_subscribe shortcode in all versions up to, and including, 2.1.10 due to insufficient input… |
| CVE-2024-35633 | Media (4.9) | 0.26% | — | 3 jun 2024 | Server-Side Request Forgery (SSRF) vulnerability in Creative Themes Blocksy Companion blocksy-companion.This issue affects Blocksy Companion: from n/a through <= 2.0.42. |
| CVE-2024-4487 | Media (5.4) | 0.43% | — | 14 may 2024 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it… |
| CVE-2024-31932 | Alta (8.8) | 0.21% | — | 11 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy Companion.This issue affects Blocksy Companion: from n/a through 2.0.28. |
| CVE-2024-2392 | Media (5.4) | 0.34% | — | 22 mar 2024 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 due to insufficient input sanitization and output… |
| CVE-2023-1911 | Media (4.3) | 0.55% | — | 2 may 2023 | The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft… |
| CVE-2023-23898 | Media (5.4) | 0.34% | — | 6 abr 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.