Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.4% | — | Themeisle Product Addons & Fields FOR Woocommerce | 26/4/2024 | 17/6/2026 | The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ppom_upload_file function in all versions up to, and including, 32.0.18. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected… | |
| Aplazada | Media (4.3) | 0.20% | — | Tychesoftwares Product Input Fields FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Product Input Fields for WooCommerce.This issue affects Product Input Fields for WooCommerce: from n/a through 1.7.0. | |
| Aplazada | Media (5.4) | 0.20% | — | Jcodex Woocommerce Checkout Field EditorAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jcodex WooCommerce Checkout Field Editor (Checkout Manager).This issue affects WooCommerce Checkout Field Editor (Checkout Manager): from n/a through 2.1.8. | |
| Aplazada | Media (6.4) | 0.43% | — | Metabox Custom Post Types Custom Fields MoreAI | 9/4/2024 | 17/6/2026 | The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and custom post meta in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping on user supplied post meta values. This makes it possible… | |
| Aplazada | Alta (7.1) | 0.35% | — | Sparkweb Interactive INC Custom Field Bulk EditorAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SparkWeb Interactive, Inc. Custom Field Bulk Editor allows Reflected XSS.This issue affects Custom Field Bulk Editor: from n/a through 1.9.1. | |
| Aplazada | Alta (8.5) | 0.55% | — | Filter Custom Fields & Taxonomies LightAI | 31/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05. | |
| Aplazada | Media (4.3) | 0.21% | — | Themelocation Custom Woocommerce Checkout Fields EditorAI | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0. | |
| Modificada | Media (6.1) | 0.42% | — | Codepeople Calculated Fields Form | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Calculated Fields Form allows Reflected XSS.This issue affects Calculated Fields Form: from n/a through 1.2.54. | |
| Modificada | Media (5.4) | 0.43% | — | Themelocation Custom Woocommerce Checkout Fields Editor | 23/3/2024 | 17/6/2026 | The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the save_wcfe_options function in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.58% | — | Smart Custom FieldsAI | 20/3/2024 | 17/6/2026 | The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 4.2.2. This makes it possible for authenticated attackers, with subscrber-level access and above, to retrieve post… | |
| Aplazada | Media (6.5) | 0.32% | — | Wpgogo Custom Field TemplateAI | 15/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template allows Stored XSS.This issue affects Custom Field Template: from n/a through 2.6. | |
| Modificada | Media (6.1) | 0.58% | — | Codepeople Calculated Fields Form | 13/3/2024 | 17/6/2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href parameter in all versions up to, and including, 5.1.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (4.3) | 0.30% | — | Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT | 13/3/2024 | 11/8/2026 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on several ajax actions. This makes it possible for unauthenticated attackers to invoke those actions via a… | |
| Analizada | Media (4.3) | 0.53% | — | Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT | 13/3/2024 | 11/8/2026 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0. This is due to missing or incorrect capability checks on several ajax actions. This makes it possible for authenticated attackers, with subscriber access or higher, to… | |
| Modificada | Media (5.4) | 0.41% | — | Gonahkar Custom Fields Shortcode | 13/3/2024 | 17/6/2026 | The Custom fields shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied custom post meta values. This makes it possible for authenticated attackers… | |
| Analizada | Crítica (9.8) | 0.59% | — | Cleanpresta CD Custom Fields 4 Orders | 8/3/2024 | 17/6/2026 | In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions. | |
| Modificada | Media (4.8) | 0.34% | — | Custom Field Suite Project Custom Field Suite | 29/2/2024 | 17/6/2026 | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on the meta values. This makes it possible for authenticated attackers, with administrator-level permissions… | |
| Modificada | Crítica (9.8) | 0.63% | — | Sysbasics Easy Checkout Field Editor | 26/2/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, Fees & Discounts: from n/a through 3.5.12. | |
| Modificada | Alta (8.8) | 1.1% | — | Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to insufficient input validation and restriction on access to that shortcode. This makes it possible… | |
| Modificada | Media (4.3) | 0.47% | — | Josevega Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.1 via the vg_display_data shortcode due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.41% | — | Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and postmeta in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Modificada | Media (5.4) | 0.52% | — | Advancedcustomfields Advanced Custom Fields | 5/2/2024 | 17/6/2026 | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Modificada | Media (5.4) | 0.48% | — | Codepeople Calculated Fields Form | 2/2/2024 | 17/6/2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULATED_FIELDS shortcode in all versions up to, and including, 1.2.52 due to insufficient input sanitization and output escaping on user supplied 'location' attribute. This makes it possible for… | |
| Modificada | Alta (7.2) | 0.75% | — | Nvidia Bluefield BMC | 24/1/2024 | 17/6/2026 | NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A successful exploit of this vulnerability may lead to code execution on the OS. | |
| Modificada | Media (4.8) | 0.47% | — | Codepeople Calculated Fields Form | 16/1/2024 | 17/6/2026 | The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) |