Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.29% | — | Ajaysharma WP Show Login FormAI | 11/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Sharma wordpress login form to anywhere wp-show-login-form allows Stored XSS.This issue affects wordpress login form to anywhere: from n/a through <= 0.2. | |
| Modificada | Alta (8.8) | 0.19% | — | Smerriman Login Logger | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in smerriman Login Logger login-logger allows Cross Site Request Forgery.This issue affects Login Logger: from n/a through <= 1.2.1. | |
| Analizada | Alta (7.1) | 0.27% | — | Forsyspress WP Login Control | 11/3/2025 | 17/6/2026 | The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Crítica (9.8) | 0.47% | — | Miniorange Social Login | 8/3/2025 | 17/6/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for… | |
| Analizada | Media (6.9) | 0.54% | — | Phpgurukul User Registration & Login AND User Management System | 7/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul User Registration & Login and User Management System 3.3. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Aplazada | Crítica (9.8) | 0.41% | — | Merkur Software B2B Login PanelAI | 5/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2B Login Panel allows SQL Injection. This issue affects B2B Login Panel: before 15.01.2025. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Homey Login RegisterAI | 5/3/2025 | 17/6/2026 | The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating… | |
| Aplazada | Alta (7.1) | 0.32% | — | Anton Aleksandrov Htaccess-login-blockAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anton Aleksandrov .htaccess Login block htaccess-login-block allows Reflected XSS.This issue affects .htaccess Login block: from n/a through <= 0.9a. | |
| Aplazada | Alta (7.1) | 0.39% | — | Jkmas Login-watchdogAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JkmAS Login Watchdog login-watchdog allows Stored XSS.This issue affects Login Watchdog: from n/a through <= 1.0.4. | |
| Aplazada | Alta (7.1) | 0.37% | — | Ashek AL Mahmud ALL IN ONE BOX LoginAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashek Al Mahmud all-in-one-box-login all-in-one-login allows Reflected XSS.This issue affects all-in-one-box-login: from n/a through <= 2.0.1. | |
| Aplazada | Alta (7.1) | 0.28% | — | Pantho Bihosh PIT Login WelcomeAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pantho Bihosh Pit Login Welcome pit-login-welcome allows Reflected XSS.This issue affects Pit Login Welcome: from n/a through <= 1.1.5. | |
| Analizada | Media (4.3) | 0.20% | — | Wpmet WP Social Login AND Register Social Counter | 28/2/2025 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function. This makes it possible for unauthenticated attackers to update… | |
| Aplazada | Crítica (9.8) | 0.41% | — | Yukseloglu Filter B2B Login PlatformAI | 27/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL Injection. This issue affects B2B Login Platform: before 16.01.2025. | |
| Modificada | Alta (8.1) | 0.59% | — | Pluginly Login ME NOW | 27/2/2025 | 17/6/2026 | The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. This is due to insecure authentication based on an arbitrary transient name in the 'AutoLogin::listen()' function. This makes it possible for unauthenticated attackers to log in an existing user on the… | |
| Analizada | Baja (3.3) | 0.15% | — | IBM Security Verify Bridge Directory SyncIBM Security Verify Gateway FOR RadiusIBM Security Verify Gateway FOR Windows Login | 22/2/2025 | 17/6/2026 | IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores potentially sensitive information in log files that could be read by a local user. | |
| Modificada | Media (5.5) | 0.14% | — | IBM Security Verify Bridge Directory SyncIBM Security Verify Gateway FOR RadiusIBM Security Verify Gateway FOR Windows Login | 21/2/2025 | 17/6/2026 | IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user. | |
| Analizada | Media (5.4) | 0.28% | — | Xootix Login/signup Popup | 20/2/2025 | 17/6/2026 | The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's xoo_el_action shortcode in all versions up to, and including, 2.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.43% | — | Umich Oidc LoginAI | 19/2/2025 | 17/6/2026 | The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_button' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Media (4.7) | 0.36% | — | Stephencarr Track Logins | 17/2/2025 | 17/6/2026 | The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Aplazada | Alta (7.1) | 0.31% | — | Fredsted WP Login Attempt LOGAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fredsted WP Login Attempt Log wp-login-attempt-log allows Reflected XSS.This issue affects WP Login Attempt Log: from n/a through <= 1.3. | |
| Aplazada | Alta (7.1) | 0.15% | — | Nagarjunsonti MY Login LogoutAI | 13/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nagarjunsonti My Login Logout Plugin my-loginlogout allows Stored XSS.This issue affects My Login Logout Plugin: from n/a through <= 2.4. | |
| Aplazada | Alta (7.1) | 0.13% | — | Danillo Nunes Login-boxAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Danillo Nunes Login-box login-box allows Stored XSS.This issue affects Login-box: from n/a through <= 2.0.4. | |
| Aplazada | Crítica (9.8) | 0.66% | — | Nextend Social Login PROAI | 7/2/2025 | 17/6/2026 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.16. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.1) | 0.32% | — | Niksudan Wp-additional-loginsAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in niksudan WordPress Additional Logins wp-additional-logins allows Reflected XSS.This issue affects WordPress Additional Logins: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.28% | — | Parswp Hide LoginAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in parswp Hide Login+ hide-login allows Reflected XSS.This issue affects Hide Login+: from n/a through <= 3.5.1. |