Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

297 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.54%—Siteorigin Page BuilderAI30/9/202630/9/2026
Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
AplazadaAlta (7.1)0.25%—Boldgrid Post AND Page BuilderAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.16%—Bold-themes Bold Page BuilderAI30/9/202630/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible…
AplazadaMedia (4.3)0.18%—Presscustomizr Nimble Page BuilderAI19/9/202621/9/2026
The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts…
AplazadaMedia (6.4)0.28%—Bold-themes Bold Page BuilderAI16/9/202616/9/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6. This is due to a bypassable security filter (bt_bb_save_pre) that can be circumvented via null byte injection,…
AplazadaMedia (6.9)0.45%—Joomshaper SP Page Builder PROAIJoomlaAI14/9/202616/9/2026
Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the result returned by the CAPTCHA plugin's onCheckAnswer event was discarded and replaced…
AplazadaMedia (5.1)0.39%—Joomshaper SP Page BuilderAI14/9/202616/9/2026
Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the relevant checks reside in the com_menus…
AplazadaMedia (6.9)0.47%—Joomshaper SP Page BuilderAI14/9/202616/9/2026
Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based destination folder in its entirety and was then passed to Folder::create() and File::upload() without either of the…
AplazadaAlta (7)0.47%—Joomshaper SP Page BuilderAI14/9/202616/9/2026
Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks used by the folder operations in the same controller, and its validation guard…
AplazadaMedia (6.9)0.45%—Joomshaper SP Page Builder PROAI14/9/202616/9/2026
Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag from the request rather than from the stored addon configuration. Verification…
AplazadaAlta (8.6)0.37%—Joomla SP Page BuilderAIJoomshaper SP Page BuilderAI14/9/202616/9/2026
Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id] from the request and concatenated it directly into the WHERE view_id = ...…
AplazadaAlta (7.1)0.13%—Export Import Wpbakery Page BuilderAI12/9/202614/9/2026
The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that…
AplazadaMedia (6.5)0.22%—Bold Page BuilderAI11/9/202611/9/2026
Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.
AplazadaMedia (6.9)0.54%—Joomlart T4 Page BuilderAI10/9/202610/9/2026
Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captcha (when no captcha plugin is enabled) and has no rate limiting. The attacker…
AplazadaMedia (6.8)0.43%—Bold-themes Bold Page BuilderAI6/9/20268/9/2026
The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
AplazadaMedia (6.8)0.43%—Bold-themes Bold Page BuilderAI5/9/20268/9/2026
The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
AplazadaMedia (6.8)0.43%—Bold-themes Bold Page BuilderAI5/9/20268/9/2026
The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link.
AplazadaMedia (6.4)0.20%—Wpbakery Page BuilderAI1/9/20261/9/2026
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
AplazadaMedia (6.4)0.36%—Greenshift Animation AND Page Builder BlocksAI26/8/202626/8/2026
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up to, and including, 12.8.9. This is due to insufficient sanitization of API responses before output via innerHTML. This makes it possible for authenticated…
AplazadaCrítica (9.3)0.39%—Joomlack Page Builder CKAI24/8/202626/8/2026
Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.
AplazadaMedia (5.3)0.44%—Joomlack Page Builder CKAI24/8/202626/8/2026
Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter.