Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2770▲ 14 respecto a la semana anterior
Críticas / altas1475▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.21%—Creativethemes Blocksy CompanionAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.
AplazadaMedia (6.4)0.33%—Creativethemes Blocksy CompanionAI1/9/20261/9/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and including, 2.1.51 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level…
AplazadaCrítica (9.8)1.1%—Creativethemes Blocksy CompanionAI9/7/20269/7/2026
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring…
AplazadaCrítica (9.2)3.6%—Blocksy Companion PROAI8/7/20268/7/2026
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom…
AplazadaCrítica (10)0.86%—Blocksy Companion PROAI2/7/20262/7/2026
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
AplazadaMedia (5.3)0.31%—Blocksy Companion PROAI26/6/202626/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.
AplazadaAlta (8.5)0.58%—Blocksy Companion PROAI26/6/202626/6/2026
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.
AplazadaMedia (4.4)0.34%—Creativethemes Blocksy CompanionAI19/6/202622/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject…
AplazadaCrítica (9.9)0.79%—Blocksy Companion PROAI17/6/202617/6/2026
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.
AplazadaCrítica (9.3)0.40%—Blocksy Companion PROAI17/6/202617/6/2026
Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.
AplazadaAlta (8.8)1.6%—Creativethemes BlocksyAI9/6/202623/7/2026
The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to insufficient input sanitization in the blocksy_sanitize_post_meta_options() function, which…
AplazadaMedia (6.4)0.27%—Creativethemes BlocksyAI2/3/202617/6/2026
The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in all versions up to, and including, 2.1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AplazadaAlta (8.8)0.69%—Creativethemes Blocksy CompanionAI11/11/202517/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to insufficient file type validation detecting SVG files, allowing double extension files to bypass sanitization while being accepted as a valid SVG file. This makes…
AplazadaMedia (6.4)0.20%—Creativethemes Blocksy CompanionAI30/10/202517/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsletter_subscribe' shortcode in all versions up to, and including, 2.1.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (6.4)0.25%—Creativethemes Blocksy CompanionAI17/9/202517/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newsletter_subscribe shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (5.9)0.18%—Creativethemes BlocksyAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq Blocksy blocksy allows Stored XSS.This issue affects Blocksy: from n/a through <= 2.1.6.
AplazadaMedia (4.9)0.38%—Creativethemes BlocksyAI7/5/202517/6/2026
Missing Authorization vulnerability in creativethemeshq Blocksy blocksy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blocksy: from n/a through <= 2.0.97.
ModificadaAlta (8.8)0.19%—Creativethemes Blocksy2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy allows Cross Site Request Forgery.This issue affects Blocksy: from n/a through <= 2.0.22.
AnalizadaMedia (5.4)0.26%—Creativethemes Blocksy5/12/202417/6/2026
The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Info Block link parameter in all versions up to, and including, 2.0.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
ModificadaMedia (5.4)0.29%—Creativethemes Blocksy5/6/202417/6/2026
The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all versions up to, and including, 2.0.50 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaMedia (4.9)0.26%—Creativethemes Blocksy Companion3/6/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Creative Themes Blocksy Companion blocksy-companion.This issue affects Blocksy Companion: from n/a through <= 2.0.42.
ModificadaMedia (5.4)0.26%—Creativethemes Blocksy21/5/202417/6/2026
The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘has_field_link_rel’ parameter in all versions up to, and including, 2.0.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
ModificadaMedia (5.4)0.43%—Creativethemes Blocksy Companion14/5/202417/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject…
ModificadaMedia (5.4)0.34%—Creativethemes Blocksy14/5/202417/6/2026
The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 2.0.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject…
ModificadaMedia (5.4)0.42%—Creativethemes Blocksy2/5/202417/6/2026
The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the className parameter in the About Me block in all versions up to, and including, 2.0.39 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above,…