Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.36% | — | Webtoffee Import Export Wordpress UsersAI | 24/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.3. | |
| Aplazada | Media (4.4) | 0.37% | — | Codection Import AND Export Users AND CustomersAI | 24/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.2. | |
| Analizada | Media (6.1) | 0.57% | — | Importwp Import WP | 24/4/2024 | 17/6/2026 | The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations. | |
| Aplazada | Media (5.9) | 0.34% | — | Extendwp Import Content IN Wordpress AND Woocommerce With ExcelAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendWP Import Content in WordPress & WooCommerce with Excel allows Reflected XSS.This issue affects Import Content in WordPress & WooCommerce with Excel: from n/a through 4.2. | |
| Modificada | Media (5.4) | 0.31% | — | Xylusthemes WP Smart Import | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WordPress Importer allows Stored XSS.This issue affects WordPress Importer: from n/a through 1.0.7. | |
| Aplazada | Alta (7.1) | 0.55% | — | Thimpress Learnpress Export ImportAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress Export Import allows Reflected XSS.This issue affects LearnPress Export Import: from n/a through 4.0.3. | |
| Modificada | Alta (7.2) | 0.38% | — | Wpallimport WP ALL Import | 15/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue affects Import Users from CSV: from n/a through 1.2. | |
| Aplazada | Media (4.3) | 0.23% | — | Webtoffee Wordpress Comments Import ExportAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.5. | |
| Aplazada | Media (4.3) | 0.20% | — | Soflyy Import ANY XML OR CSV File TO WordpressAI | 10/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Import any XML or CSV File to WordPress.This issue affects Import any XML or CSV File to WordPress: from n/a through 3.7.3. | |
| Aplazada | Media (6.4) | 0.45% | — | Template KIT ImportAI | 9/4/2024 | 17/6/2026 | The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload functionality in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access and above, to… | |
| Aplazada | Media (6.6) | 0.28% | — | Nmap ImporterAIMicrosoft Windows RegistryAI | 8/4/2024 | 17/6/2026 | The NMAP Importer service may expose data store credentials to authorized users of the Windows Registry. | |
| Modificada | Alta (7.2) | 0.40% | — | Vjinfotech WP Import Export Lite | 7/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26. | |
| Aplazada | Alta (7.2) | 0.60% | — | Mooveagency Import XML AND RSS FeedsAI | 7/4/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: from n/a through 2.1.5. | |
| Aplazada | Alta (7.6) | 0.49% | — | Thimpress Learnpress Export ImportAI | 7/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress LearnPress Export Import.This issue affects LearnPress Export Import: from n/a through 4.0.3. | |
| Aplazada | Media (4.3) | 0.52% | — | Webtoffee Import Export Wordpress UsersAI | 29/3/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.2. | |
| Modificada | Media (6.1) | 0.40% | — | Xylusthemes WP Smart Import | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WordPress Importer allows Reflected XSS.This issue affects WordPress Importer: from n/a through 1.0.4. | |
| Modificada | Alta (7.2) | 0.60% | — | Webtoffee Product Import Export FOR Woocommerce | 26/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.4.1. | |
| Modificada | Crítica (9.8) | 0.58% | — | Olivethemes Olive ONE Click Demo Import | 20/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. | |
| Analizada | Crítica (9.8) | 0.53% | — | Myprestamodules Product Catalog (csv, Excel) Import | 3/3/2024 | 17/6/2026 | SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods. | |
| Analizada | Crítica (9.1) | 0.79% | — | Myprestamodules Product Catalog (csv, Excel) Import | 27/2/2024 | 17/6/2026 | In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php. | |
| Analizada | Crítica (9.8) | 0.57% | — | Prestashop Import/update Bulk Product | 27/2/2024 | 17/6/2026 | In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions. | |
| Modificada | Alta (7.2) | 1.5% | — | Firebearstudio Improved Import & Export | 16/2/2024 | 17/6/2026 | A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file. | |
| Modificada | Alta (7.2) | 0.53% | — | Webtoffee Product Import Export FOR Woocommerce | 24/1/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.3.7. | |
| Modificada | Alta (7.2) | 0.53% | — | Webtoffee Order Export & Order Import FOR Woocommerce | 24/1/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.3. | |
| Modificada | Alta (7.2) | 1.2% | — | Themely Theme Demo Import | 16/1/2024 | 17/6/2026 | Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed. |