Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.82% | — | Signup SigninAI | 24/6/2026 | 29/6/2026 | The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore… | |
| Aplazada | Alta (8.8) | 0.27% | — | WOW Viral SignupsAI | 9/6/2026 | 21/7/2026 | Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup'… | |
| Aplazada | Alta (7.1) | 0.11% | — | Fanbridge SignupAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FanBridge FanBridge signup fanbridge-signup allows Stored XSS.This issue affects FanBridge signup: from n/a through <= 0.6. | |
| Aplazada | Media (4.3) | 0.13% | — | Custom Login AND Signup WidgetAI | 20/9/2025 | 17/6/2026 | The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation in the /frndzk_adminclsw.php file. This makes it possible for unauthenticated attackers to change the email and username… | |
| Analizada | Crítica (9.8) | 0.41% | — | Vishnusivadas Login-signup | 22/8/2025 | 17/6/2026 | The LogIn-SignUp project by VishnuSivadasVS is vulnerable to SQL Injection due to unsafe construction of SQL queries in DataBase.php. The functions logIn() and signUp() build queries by directly concatenating user input and unvalidated table names without using prepared statements. While a prepareData() function… | |
| Aplazada | Crítica (9.1) | 2.4% | 💥 Exploit | Bitto.kazi Custom Login AND Signup WidgetAI | 1/7/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget allows Code Injection.This issue affects Custom Login And Signup Widget: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.17% | — | UI Ucrm Client Signup PluginAI | 29/6/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default. | |
| Analizada | Media (5.4) | 0.28% | — | Xootix Login/signup Popup | 20/2/2025 | 17/6/2026 | The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's xoo_el_action shortcode in all versions up to, and including, 2.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (6.5) | 0.39% | — | Modalsurvey Simple Signup Form | 18/2/2025 | 17/6/2026 | The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, and including, 1.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.54% | — | Alphabpo Easy Newsletter SignupsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in AlphaBPO Easy Newsletter Signups allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Newsletter Signups: from n/a through 1.0.4. | |
| Aplazada | Crítica (9.8) | 1.3% | 💥 PoC | Scott Gamon Signup PageAI | 29/10/2024 | 17/6/2026 | Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affects Signup Page: from n/a through <= 1.0. | |
| Analizada | Crítica (9.8) | 3.3% | 💥 Exploit | Wow-company Viral Signup | 4/9/2024 | 17/6/2026 | The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | |
| Analizada | Media (4.8) | 0.37% | — | Wow-company Viral Signup | 29/8/2024 | 17/6/2026 | The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.3) | 0.36% | — | Xootix Login/signup Popup | 6/6/2024 | 17/6/2026 | The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ‘export_settings’ function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read… | |
| Modificada | Alta (8.8) | 1.5% | 💥 PoC | Xootix Login/signup PopupXootix OTP Login Woocommerce & Gravity FormsXootix Side Cart WoocommerceXootix Waitlist Woocommerce | 6/6/2024 | 17/6/2026 | Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary… | |
| Aplazada | Media (5.3) | 0.50% | — | Mailerlite Signup FormsAI | 2/5/2024 | 17/6/2026 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due to a missing capability check on the toggleRolesAndPermissions and editAllowedRolesAndPermissions functions in all versions up to, and including, 1.7.6. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.42% | — | Mailerlite Signup FormsAI | 2/5/2024 | 17/6/2026 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions 1.5.0 to 1.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Analizada | Alta (7.5) | 0.83% | — | Keerti1924 PHP Mysql User Signup Login System | 7/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. This affects an unknown part of the file login.sql. The manipulation leads to inclusion of sensitive information in source code. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Crítica (9.8) | 0.60% | — | Keerti1924 PHP Mysql User Signup Login System | 7/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.66% | — | Keerti1924 PHP Mysql User Signup Login System | 21/2/2024 | 17/6/2026 | A vulnerability was found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /edit.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Crítica (9.8) | 0.81% | — | Keerti1924 PHP Mysql User Signup Login System | 21/2/2024 | 17/6/2026 | A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.4) | 0.58% | — | Keerti1924 PHP Mysql User Signup Login System | 21/2/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument username with the input <script>alert("xss")</script> leads to cross site scripting. It is possible to launch the… | |
| Modificada | Alta (7.2) | 0.96% | — | Alphabpo Easy Newsletter Signups | 4/12/2023 | 17/6/2026 | The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | |
| Modificada | Alta (8.8) | 0.25% | — | Laposta Signup Basic | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Laposta - Roel Bousardt Laposta Signup Basic plugin <= 1.4.1 versions. | |
| Modificada | Media (4.6) | 0.70% | — | Xootix Login/signup Popup | 7/6/2023 | 17/6/2026 | The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin settings that execute if they can… |