Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | If-so Dynamic ContentAI | 7/10/2026 | 7/10/2026 | The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link. | |
| Pendiente de análisis | Media (5.3) | — | — | Opentext Content ServerAI | 6/10/2026 | 6/10/2026 | Cross-site Scripting (XSS) in the Forums feature of OpenText Content Management Content Server could allow a bad actor to inject malicious code into a Forums web page. | |
| Aplazada | Media (4.3) | 0.15% | — | WDS MCP Content ManagerAI | 6/10/2026 | 6/10/2026 | Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions. | |
| Pendiente de análisis | Media (6.9) | 0.39% | — | Joomlafry TF ContentAI | 5/10/2026 | 6/10/2026 | Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, content-binding, or cron-token enforcement. A Guest can supply the numeric ID of… | |
| Pendiente de análisis | Media (6.9) | 0.26% | — | Joomlafry TF ContentAI | 5/10/2026 | 6/10/2026 | Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the… | |
| Aplazada | Media (4.3) | 0.15% | — | Deepak Anand WP Dummy Content GeneratorAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0. | |
| Aplazada | Alta (8.1) | 0.29% | — | Nelio ContentAI | 3/10/2026 | 6/10/2026 | The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Baja (3.1) | 0.12% | — | If-so Dynamic ContentAI | 1/10/2026 | 1/10/2026 | The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page. | |
| Aplazada | Media (4.7) | 0.18% | — | IF SO Dynamic ContentAI | 1/10/2026 | 1/10/2026 | The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who opens a crafted link. | |
| Aplazada | Media (6.5) | 0.28% | — | MCP Content Manager LiteAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Keywordrush Content EGGAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | If-so Dynamic Content PersonalizationAI | 30/9/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Reflected XSS.This issue affects If-So Dynamic Content Personalization: from n/a through 1.10.1. | |
| Aplazada | Media (6.8) | 0.24% | — | Keywordrush Content EGGAI | 30/9/2026 | 30/9/2026 | The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary… | |
| Pendiente de análisis | Media (6.5) | 0.76% | — | Plone APP DexterityAIPlone APP ContenttypesAI | 22/9/2026 | 25/9/2026 | plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, and plone.app.contenttypes versions through 3.0.11, 4.0.0 through 4.0.9, and 5.0.0… | |
| Pendiente de análisis | Media (5.5) | 0.25% | — | Adobe Content CredentialsAI | 22/9/2026 | 23/9/2026 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a… | |
| Pendiente de análisis | Media (4.3) | 1.0% | — | CAI Content CredentialsAI | 22/9/2026 | 22/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim… | |
| En análisis | Media (6.5) | 1.3% | — | CAI Content CredentialsAI | 22/9/2026 | 25/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must… | |
| En análisis | Media (4.3) | 1.0% | — | CAI Content CredentialsAI | 22/9/2026 | 22/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim… | |
| En análisis | Media (5.5) | 0.24% | — | CAI Content CredentialsAI | 22/9/2026 | 26/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim… | |
| En análisis | Alta (7.5) | 0.90% | — | CAI Content CredentialsAI | 22/9/2026 | 23/9/2026 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user… | |
| En análisis | Alta (7.5) | 0.65% | — | CAI Content CredentialsAI | 22/9/2026 | 22/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. | |
| Aplazada | Alta (8.8) | 0.57% | — | BM Content BuilderAI | 22/9/2026 | 22/9/2026 | The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding, 3.17.1. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.5) | 0.53% | — | BM Content BuilderAI | 22/9/2026 | 22/9/2026 | The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Webcenter ContentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to… | |
| Aplazada | Alta (7.7) | 0.41% | — | Contentful MCP ServerAIContentful MCP ToolsAI | 15/9/2026 | 30/9/2026 | Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-to-space-migration/exportSpace.ts and… |