Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1392 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.29%—Udesign CoreAI6/10/20266/10/2026
Subscriber SQL Injection in UDesign Core <= 4.15.0 versions.
AplazadaAlta (7.1)0.24%—Prestalife Product DesignerAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Lumise Product Designer <= 2.1.1 versions.
AplazadaCrítica (9.9)0.74%—Woocommerce Designer PROAI6/10/20266/10/2026
Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions.
AplazadaMedia (6.5)0.36%—Semperfiwebdesign ALL IN ONE SEOAI3/10/20266/10/2026
The The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.2 This is due to the software allowing users to execute an action that does not properly…
AplazadaMedia (5.3)0.21%—Emarketdesign Request A QuoteAI2/10/20262/10/2026
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
AplazadaAlta (8.8)0.36%—DesignsetgoAI30/9/202630/9/2026
Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.
AplazadaAlta (7.2)0.40%—Kadencewp Kadence Woocommerce Email DesignerAI30/9/202630/9/2026
Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.
AplazadaAlta (7.5)0.90%—Product Designer APPAI30/9/202630/9/2026
The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The…
AplazadaAlta (7.2)0.27%—Radykal Fancy Product DesignerAI25/9/202625/9/2026
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
AplazadaAlta (7.2)0.21%—Radykal Fancy Product DesignerAI25/9/202625/9/2026
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
AplazadaAlta (7.2)0.19%—Radykal Fancy Product DesignerAI25/9/202625/9/2026
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (6.5)0.17%—Etoilewebdesign Ultimate FAQAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.
Pendiente de análisisMedia (5.5)0.14%—Adobe IndesignAI22/9/202625/9/2026
InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must…
Pendiente de análisisMedia (5.5)0.18%—Adobe IndesignAI22/9/202622/9/2026
InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must…
AplazadaCrítica (9.8)0.55%—WEB TO Print Online DesignerAI21/9/202621/9/2026
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.
AplazadaMedia (4.3)0.14%—Fetchdesigns Sign-up SheetsAI20/9/202621/9/2026
The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.
AplazadaAlta (7.5)0.94%—Printcart WEB TO Print Product DesignerAI18/9/202618/9/2026
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain…
AplazadaMedia (5.1)0.36%—Design Scuole ItaliaAI15/9/202618/9/2026
The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).
AplazadaMedia (5.1)0.51%—Design Scuole ItaliaAI15/9/202618/9/2026
The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted URL containing a malicious archive parameter.
AplazadaAlta (8.7)0.46%—Design Scuole ItaliaAI15/9/202618/9/2026
The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/…
AplazadaAlta (8.7)0.54%—Wordpress Design Scuole ItaliaAI15/9/202618/9/2026
A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.
AplazadaAlta (7.5)0.35%—Shirt Product DesignerAI10/9/202610/9/2026
Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
AplazadaAlta (7.2)0.42%—Codesigner User Profile BuilderAI7/9/20269/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This…
AplazadaMedia (6.4)0.33%—Codesigner User Profile BuilderAI1/9/20261/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaMedia (6.1)0.25%—Ceviz Informatics INC WEB DesignAI28/8/202631/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026.