Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
721 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Wpsocialrocket Social RocketAI | 6/10/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Socialrocket Social Rocket social-rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.5. | |
| Aplazada | Media (6.5) | 0.29% | — | 10web Social Photo FeedAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions. | |
| Aplazada | Media (5.5) | 0.26% | — | MoosocialAI | 4/10/2026 | 6/10/2026 | A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (6.4) | 0.19% | — | Wpmet WP Social Login AND Register Social CounterAI | 3/10/2026 | 6/10/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.2) | 0.27% | — | Smashballoon Social Post FeedAI | 2/10/2026 | 3/10/2026 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message via v-html in Admin Builder Preview in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Alta (7.6) | 0.30% | — | Social BoostAI | 1/10/2026 | 1/10/2026 | Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. | |
| Aplazada | Media (6.1) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 1/10/2026 | 3/10/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (5.9) | 0.19% | — | Nextscripts Social Networks Auto PosterAI | 27/9/2026 | 28/9/2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials,… | |
| Aplazada | Media (4.3) | 0.32% | — | Adenion Blog2socialAI | 25/9/2026 | 25/9/2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Pendiente de análisis | Media (4.2) | 0.16% | — | Python Social AuthAI | 24/9/2026 | 30/9/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to… | |
| Pendiente de análisis | Alta (7.4) | 0.16% | — | Python Social AuthAI | 24/9/2026 | 28/9/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a… | |
| Pendiente de análisis | Media (4.3) | 0.11% | — | Python Social AuthAI | 24/9/2026 | 5/10/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication… | |
| Pendiente de análisis | Media (6.8) | 0.22% | — | Python Social AuthAI | 24/9/2026 | 29/9/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could… | |
| Pendiente de análisis | Media (6.4) | 0.23% | — | Python Social AuthAI | 24/9/2026 | 5/10/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Moodle SocialwallAI | 23/9/2026 | 24/9/2026 | SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests | |
| Aplazada | Media (5.3) | 0.18% | — | Social Commerce FOR WoocommerceAI | 23/9/2026 | 23/9/2026 | The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state. | |
| Aplazada | Media (4.4) | 0.21% | — | Wp2social Auto PublishAI | 19/9/2026 | 21/9/2026 | The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Media (5.3) | 0.30% | — | Adenion Blog2socialAI | 16/9/2026 | 24/9/2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts table using only the attacker-supplied b2s_id primary key with no blog_user_id… | |
| Aplazada | Media (5.3) | 0.28% | — | Adenion Blog2socialAI | 16/9/2026 | 24/9/2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php invokes B2S_Tools::searchUser() in includes/Tools.php, which returns the email address of every matching user without… | |
| Aplazada | Media (5.3) | 0.28% | — | Adenion Blog2socialAI | 16/9/2026 | 24/9/2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the owner parameter to display names without verifying that the caller is authorized to… | |
| Aplazada | Media (5.1) | 0.34% | — | Yamap - Social Trekking GPS APPAI | 14/9/2026 | 16/9/2026 | The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage from the app or redirect users to unintended websites. | |
| Aplazada | Alta (7.1) | 0.35% | — | Avideo SocialmediapublisherAIWwbn AvideoAI | 8/9/2026 | 8/9/2026 | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored… | |
| Aplazada | Media (6.4) | 0.20% | — | Social Chat Click TO Chat APP ButtonAI | 5/9/2026 | 8/9/2026 | The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.18% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button.… | |
| Aplazada | Media (6.8) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts… |