Realtyna
Realtyna Organic IDX: vulnerabilidades y CVE
Realtyna Organic IDX tiene 11 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses7
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-91014 | Alta (7.1) | 0.28% | — | 17 sept 2026 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run… |
| CVE-2026-78261 | Alta (7.1) | 0.25% | — | 27 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. |
| CVE-2026-16236 | Alta (8.8) | 1.2% | — | 31 jul 2026 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function… |
| CVE-2026-14483 | Crítica (9.8) | 4.0% | — | 31 jul 2026 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type… |
| CVE-2026-13714 | Crítica (9.8) | 0.83% | — | 27 jul 2026 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and… |
| CVE-2026-57811 | Crítica (10) | 0.56% | — | 13 jul 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX… |
| CVE-2026-45439 | Crítica (9.3) | 0.40% | — | 15 jun 2026 | Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions. |
| CVE-2025-54052 | Alta (7.5) | 0.21% | — | 20 ago 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows PHP Local File Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through… |
| CVE-2024-38736 | Crítica (9.1) | 0.49% | — | 12 jul 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.13. |
| CVE-2024-33924 | Alta (7.1) | 0.33% | — | 3 may 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Realtyna Realtyna Organic IDX plugin allows Reflected XSS.This issue affects Realtyna Organic IDX plugin: from n/a… |
| CVE-2024-32128 | Crítica (9.3) | 1.7% | — | 15 abr 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna Organic IDX plugin.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.4. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.