Themeum
Themeum Qubely: vulnerabilidades y CVE
Themeum Qubely tiene 10 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-65531 | Media (4.8) | 0.22% | — | 23 jul 2026 | Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. |
| CVE-2026-39638 | Media (5.9) | 0.24% | — | 8 abr 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= 1.8.14. |
| CVE-2025-58663 | Media (4.3) | 0.24% | — | 22 sept 2025 | Missing Authorization vulnerability in Themeum Qubely qubely allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Qubely: from n/a through <= 1.8.14. |
| CVE-2025-58249 | Media (4.3) | 0.27% | — | 22 sept 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Themeum Qubely qubely allows Retrieve Embedded Sensitive Data.This issue affects Qubely: from n/a through <= 1.8.14. |
| CVE-2024-13228 | Media (6.5) | 0.36% | — | 11 mar 2025 | The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for… |
| CVE-2025-26767 | Media (5.4) | 0.22% | — | 16 feb 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= 1.8.12. |
| CVE-2024-9601 | Media (5.4) | 0.33% | — | 14 feb 2025 | The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in all versions up to, and including, 1.8.12 due to insufficient input… |
| CVE-2023-0376 | Media (5.4) | 0.74% | — | 16 ene 2024 | The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and… |
| CVE-2021-24916 | Alta (7.5) | 1.7% | — | 7 ago 2023 | The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action. |
| CVE-2021-25013 | Media (6.5) | 0.43% | — | 24 ene 2022 | The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any… |