Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.34% | — | GetcontentfromurlAI | 14/1/2026 | 17/6/2026 | The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0. This is due to the plugin using wp_remote_get() instead of wp_safe_remote_get() to fetch content from a user-supplied URL in the 'url' parameter of the [gcfu] shortcode. This makes it… | |
| Aplazada | Crítica (9.1) | 0.41% | — | ContentstudioAI | 8/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.This issue affects Contentstudio: from n/a through <= 1.3.7. | |
| Analizada | Media (5.5) | 0.39% | — | Code-projects Content Management System | 2/1/2026 | 17/6/2026 | A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. | |
| Analizada | Baja (2) | 0.36% | — | Code-projects Content Management System | 2/1/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown function of the file /admin/edit_posts.php. The manipulation of the argument image leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed publicly… | |
| Modificada | Media (5.5) | 0.39% | — | Code-projects Content Management System | 2/1/2026 | 17/6/2026 | A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processing of the file /admin/delete.php. Executing a manipulation of the argument del can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.5) | 0.44% | — | Code-projects Content Management System | 2/1/2026 | 17/6/2026 | A vulnerability was determined in code-projects Content Management System 1.0. This impacts an unknown function of the file search.php. This manipulation of the argument Value causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (4.3) | 0.18% | — | Recorp Ai-content-writing-assistantAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in recorp AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One ai-content-writing-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Content Writing Assistant (Content Writer, ChatGPT, Image… | |
| Aplazada | Media (6.5) | 0.19% | — | Bainternet User Specific ContentAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bainternet User Specific Content user-specific-content allows DOM-Based XSS.This issue affects User Specific Content: from n/a through <= 1.0.6. | |
| Aplazada | Media (6.5) | 0.19% | — | Ruhul Amin Content FetcherAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ruhul Amin Content Fetcher content-fetcher allows DOM-Based XSS.This issue affects Content Fetcher: from n/a through <= 1.1. | |
| Analizada | Baja (2) | 0.34% | — | Anirbandutta News-buzzCode-projects Content Management System | 29/12/2025 | 7/10/2026 | A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Alta (7.1) | 0.18% | — | Councilsoft Content Grid SliderAI | 29/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in councilsoft Content Grid Slider content-grid-slider allows Reflected XSS.This issue affects Content Grid Slider: from n/a through <= 1.5. | |
| Aplazada | Media (6.4) | 0.24% | — | Membership Plugin Restrict ContentAI | 23/12/2025 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (5.4) | 0.12% | — | Semrush CY LTD Semrush Content ToolkitAI | 16/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SEMrush CY LTD Semrush Content Toolkit semrush-contentshake allows Cross Site Request Forgery.This issue affects Semrush Content Toolkit: from n/a through <= 1.1.32. | |
| Aplazada | Media (5.3) | 0.32% | — | Ays-pro Secure Copy Content Protection AND Content LockingAI | 12/12/2025 | 17/6/2026 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in a publicly accessible directory with predictable filenames in all versions up to, and including, 4.9.2. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.16% | — | Ays-pro Secure Copy Content Protection AND Content LockingAI | 12/12/2025 | 17/6/2026 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.2. This is due to missing nonce validation on the 'ays_sccp_results_export_file' AJAX action. This makes it possible for unauthenticated attackers to export… | |
| Aplazada | Media (4.3) | 0.16% | — | Badi Jones Duplicate Content CureAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Badi Jones Duplicate Content Cure duplicate-content-cure allows Cross Site Request Forgery.This issue affects Duplicate Content Cure: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.54% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI | 9/12/2025 | 17/6/2026 | SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application. | |
| Aplazada | Media (4.3) | 0.16% | — | ContentstudioAI | 5/12/2025 | 17/6/2026 | The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or insufficient nonce validation on the add_cstu_settings function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request… | |
| Aplazada | Alta (8.8) | 0.61% | — | ContentstudioAI | 5/12/2025 | 17/6/2026 | The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the… | |
| Aplazada | Media (5.3) | 0.28% | — | AYS Code AI Chatbot With Chatgpt AND Content GeneratorAI | 27/11/2025 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files. | |
| Aplazada | Media (6.5) | 0.29% | — | AYS AI Chatbot With Chatgpt AND Content GeneratorAI | 27/11/2025 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.0 via the ays_chatgpt_pinecone_upsert function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations… | |
| Aplazada | Media (5.3) | 0.29% | — | Locker ContentAI | 25/11/2025 | 17/6/2026 | The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'lockerco_submit_post' AJAX endpoint. This makes it possible for unauthenticated attackers to extract content from posts that has been protected by the plugin. | |
| Aplazada | Media (5.4) | 0.20% | — | Pluginever WP Content PilotAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in PluginEver WP Content Pilot wp-content-pilot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Content Pilot: from n/a through <= 2.1.7. | |
| Aplazada | Media (6.4) | 0.22% | — | Wordpress Content FlipperAI | 13/11/2025 | 17/6/2026 | The WordPress Content Flipper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bgcolor' shortcode attribute of the 'flipper_front' shortcode in all versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.32% | — | Specific Content FOR MobileAI | 12/11/2025 | 17/6/2026 | The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable to SQL Injection via the eos_scfm_duplicate_post_as_draft() function in all versions up to, and including, 0.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient… |