Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
1419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.24% | — | Crocoblock JetformbuilderAI | 2/10/2026 | 2/10/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.2) | 0.31% | — | Kubio AI Page BuilderAI | 2/10/2026 | 2/10/2026 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Alta (8.5) | 0.21% | — | Villatheme WOO Product BuilderAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a… | |
| Aplazada | Alta (7.2) | 0.30% | — | Siteorigin Page BuilderAI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Crocoblock JetformbuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Boldgrid Post AND Page BuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. | |
| Aplazada | Media (6.5) | 0.13% | — | Visualcomposer Visual Composer Website BuilderAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions. | |
| Aplazada | Alta (8.8) | 0.36% | — | Themify BuilderAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Cozmoslabs Profile BuilderAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions. | |
| Aplazada | Media (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 30/9/2026 | 30/9/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 30/9/2026 | 30/9/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible… | |
| Aplazada | Media (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 30/9/2026 | 30/9/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 30/9/2026 | 30/9/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 30/9/2026 | 30/9/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible… | |
| Aplazada | Alta (7.2) | 0.26% | — | User Profile BuilderAI | 25/9/2026 | 25/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.27% | — | Themify BuilderAI | 25/9/2026 | 25/9/2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.4) | 0.20% | — | Codeselling User Profile BuilderAI | 25/9/2026 | 25/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.21% | — | Crocoblock JetformbuilderAI | 25/9/2026 | 25/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 2.9% | — | Visualcomposer Visual Composer Website BuilderAI | 24/9/2026 | 24/9/2026 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP… | |
| Aplazada | Alta (8.6) | 0.27% | — | Jet-form-builder-stripe-gatewayAI | 23/9/2026 | 23/9/2026 | The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes. | |
| Aplazada | Crítica (9.8) | 0.66% | — | Ph7software Ph7builderAI | 22/9/2026 | 23/9/2026 | pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the admin login attempt counter and lockout are keyed on this… | |
| Aplazada | Media (6.5) | 0.50% | — | Ph7software Ph7builderAI | 22/9/2026 | 23/9/2026 | Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form element is only built when that flag is present, so a remote… | |
| Aplazada | Alta (7.1) | 0.56% | — | Wptablebuilder WP Table BuilderAI | 22/9/2026 | 22/9/2026 | The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.2.1. This is due to an operator precedence bug in the post-type guard within the trash_table_bulk() and restore_table_bulk() functions that causes the guard to never… | |
| Aplazada | Alta (8.8) | 0.57% | — | BM Content BuilderAI | 22/9/2026 | 22/9/2026 | The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding, 3.17.1. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.5) | 0.53% | — | BM Content BuilderAI | 22/9/2026 | 22/9/2026 | The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the… |