Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

289 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.3%💥 ExploitWpmanageninja Ninja JOB Board22/8/202217/6/2026
The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.
ModificadaMedia (4.8)0.59%—Ninjateam WP Duplicate Page11/7/202217/6/2026
The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
ModificadaMedia (4.8)0.59%—Ninjaforms Ninja Forms4/7/202217/6/2026
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (4.8)0.59%—Ninjaforms Ninja Forms4/7/202217/6/2026
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (4.8)0.50%—Ninjaforms Ninja Forms16/6/202217/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".
ModificadaMedia (4.8)0.60%—Commonninja Easily Generate Rest API9/5/202217/6/2026
The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaAlta (7.5)11%💥 ExploitCommoninja Videos Sync PDF25/4/202217/6/2026
The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues
ModificadaMedia (6.1)0.78%—Ninjaforms Ninja Forms File Uploads23/3/202217/6/2026
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable…
ModificadaCrítica (9.8)39%—Ninjaforms Ninja Forms File Uploads23/3/202217/6/2026
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to…
ModificadaMedia (4.8)0.69%—Wpmanageninja Ninja Tables1/2/202217/6/2026
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (5.4)0.59%—Invoiceninja Invoice Ninja24/12/202117/6/2026
invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaAlta (7.2)1.3%—Ninjaforms Ninja Forms29/11/202117/6/2026
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks
ModificadaMedia (4.8)0.62%—Ninjaforms Contact Form25/10/202117/6/2026
The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (4.3)0.66%—Ninjaforms Ninja Forms22/9/202117/6/2026
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the…
ModificadaMedia (6.5)1.2%—Ninjaforms Ninja Forms22/9/202117/6/2026
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the…
ModificadaMedia (5.4)0.62%—Wpmanageninja Fluentsmtp30/8/202117/6/2026
The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the values before outputting them when viewing the SMTP settings set by this plugin, leading to a stored cross site scripting (XSS) vulnerability. Only users with roles…
ModificadaCrítica (9.8)2.8%—Ninjateam Filebird12/7/202117/6/2026
The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL injection. The Rest API endpoint which…
ModificadaAlta (7.1)0.36%—Ninjarmm7/7/202117/6/2026
The Agent in NinjaRMM 5.0.909 has Insecure Permissions.
ModificadaAlta (7.8)0.38%—Ninjarmm7/7/202117/6/2026
The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.
ModificadaAlta (7.5)2.0%—Ninjateam Video Downloader FOR Tiktok7/7/202117/6/2026
Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.
ModificadaCrítica (9.8)1.7%—Ninjateam Video Downloader FOR Tiktok7/7/202117/6/2026
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open ports, local network hosts and execute…
ModificadaAlta (7.8)2.4%—Vector35 Binary Ninja29/6/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Vector 35 Binary Ninja 2.3.2660 (Build ID 88f343c3). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaAlta (7.8)2.4%—Vector35 Binary Ninja29/6/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Vector 35 Binary Ninja 2.3.2660 (Build ID 88f343c3). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaAlta (8.1)1.8%—Invoiceninja Invoice Ninja6/6/202117/6/2026
In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can result in remote code execution. The attacker's input must be hosted at http://www.geoplugin.net…
ModificadaMedia (5.4)0.46%—Ninjaforms Ninja Forms5/4/202117/6/2026
The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.
Orbitaley — Vulnerabilidades