Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.21%—Joomsky JS Support TicketAI5/10/20266/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through 4.0.0.
AplazadaMedia (4.3)0.16%—Helpdesk Support Ticket System FOR WoocommerceAI3/10/20266/10/2026
The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level…
AplazadaMedia (6.5)0.27%—SupportcandyAI3/10/20266/10/2026
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' parameter in all versions up to, and including, 3.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AplazadaMedia (6.4)0.20%—SupportcandyAI3/10/20266/10/2026
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (5.3)0.20%—Uvdesk Support Center BundleAI2/10/20266/10/2026
UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to…
AplazadaMedia (4.3)0.17%—Majesticsupport Majestic SupportAI1/10/20261/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.
AplazadaMedia (5.3)0.18%—Majesticsupport Majestic SupportAI1/10/20261/10/2026
Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.
AplazadaMedia (6.4)0.20%—Awesomesupport Awesome SupportAI1/10/20261/10/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.24%—Awesomesupport Awesome SupportAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.
AplazadaMedia (5.4)0.23%—Wpmanageninja Fluent SupportAI23/9/202623/9/2026
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
Pendiente de análisisAlta (7.3)0.11%—HP Support AssistantAI22/9/202629/9/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
AplazadaMedia (5.3)0.34%—SupportcandyAI9/9/20269/9/2026
The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket.
AplazadaMedia (5.3)0.34%—SupportcandyAI9/9/20269/9/2026
The SupportCandy WordPress plugin before 3.5.3 does not perform an authorization check on one of its support-ticket attachment download paths, allowing unauthenticated attackers to read protected customer-uploaded attachments by enumerating sequential attachment identifiers.
AplazadaMedia (4.3)0.24%—Awesomesupport Awesome SupportAI9/9/202611/9/2026
The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or…
Pendiente de análisisAlta (7.3)0.09%—HP Support AssistantAI3/9/20268/9/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
AplazadaAlta (8.8)0.40%—Support GenixAI1/9/20262/9/2026
The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()` function and its `p` parameter. This is due to…
AplazadaMedia (5.4)0.13%—Fluent Support PROAI24/8/202624/8/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
AplazadaMedia (5.4)0.23%—Fluent Support PROAI24/8/202624/8/2026
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
AplazadaAlta (8.2)0.41%—SupportcandyAI18/8/202620/8/2026
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
AplazadaMedia (6.1)0.25%—Benbodhi SVG SupportAI3/8/202626/8/2026
The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the…
AplazadaMedia (5.3)0.71%—Support GenixAI1/8/202626/8/2026
The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthenticated attackers to read arbitrary files with an allowlisted extension — including other users' private ticket attachments — from the server.
AplazadaBaja (3.8)0.26%—Wpmanageninja Fluent SupportAI1/8/202626/8/2026
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.
AplazadaBaja (3.7)0.26%—Support GenixAI31/7/202626/8/2026
The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.
AplazadaMedia (5.3)0.47%—Wpbot AI Chatbot FOR Live Support Lead Generation AI ServicesAI28/7/202628/7/2026
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and…
AplazadaMedia (6.4)0.34%—Wpmanageninja Fluent SupportAI24/7/202624/7/2026
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…