Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
2432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.42% | — | Pluginops Mailchimp Subscribe FormAI | 1/8/2026 | 12/8/2026 | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.5) | 0.41% | — | Wp-feedstats Wordpress PluginAI | 31/7/2026 | 26/8/2026 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes. | |
| Aplazada | Media (6.5) | 0.60% | — | Sylius Mollie PluginAI | 30/7/2026 | 10/9/2026 | Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints look up sequential orderId values without… | |
| Aplazada | Alta (7.5) | 0.68% | — | Sylius Mollie PluginAI | 30/7/2026 | 10/9/2026 | Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced Sylius… | |
| Aplazada | Media (5.3) | 0.34% | — | Appointment Booking PluginAI | 30/7/2026 | 30/7/2026 | The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval… | |
| Aplazada | Media (5.4) | 0.26% | — | Wpplugins Hide MY WP GhostAI | 30/7/2026 | 30/7/2026 | The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP address to bypass the WP Ghost (Hide My WP Ghost) WordPress plugin before… | |
| Pendiente de análisis | Alta (8.3) | 0.42% | — | Linuxfabrik Monitoring-pluginsAIIcingaAINagiosAI | 29/7/2026 | 30/7/2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect… | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | Linuxfabrik Monitoring-pluginsAIPython Sqlite3AI | 29/7/2026 | 30/7/2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would… | |
| Aplazada | Media (6.3) | 0.24% | — | Grav Login PluginAI | 29/7/2026 | 30/7/2026 | Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout… | |
| Aplazada | Media (6.5) | 0.41% | — | Plugin OrganizerAI | 28/7/2026 | 28/7/2026 | The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4. This is due to insufficient escaping on the user-supplied parameter in the perform_plugin_search() function, where esc_sql() output is passed as the replacement string… | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Format Plugins | 28/7/2026 | 5/8/2026 | Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Pendiente de análisis | Baja (3.3) | 0.12% | — | Gstreamer Gst-plugins-goodAIMatroskaAIWebmAI | 28/7/2026 | 28/7/2026 | A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a boundary check that does not account for the full size of the data being copied, allowing a… | |
| Aplazada | Alta (8.8) | 0.73% | — | Eazy Plugin ManagerAI | 28/7/2026 | 28/7/2026 | The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the `wp_ajax_pos_get_option` AJAX handler, which verifies only a nonce that is localized to… | |
| Aplazada | Alta (7.5) | 0.51% | — | Pickplugins Question AnswerAI | 28/7/2026 | 28/7/2026 | The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which removes WordPress's magic… | |
| Aplazada | Alta (7.5) | 0.48% | — | Booking-wp-plugin BooklyAI | 28/7/2026 | 28/7/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Media (6.5) | 0.22% | — | 100plugins Open User MAPAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Shapedplugin Location WeatherAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions. | |
| Aplazada | Alta (7.4) | 0.39% | — | Wpplugins Hide MY WP GhostAI | 27/7/2026 | 27/7/2026 | Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. | |
| Aplazada | Media (5.1) | 0.40% | — | MilkdownAIMilkdown Plugin EmojiAI | 24/7/2026 | 27/7/2026 | Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's origin by causing a victim to paste attacker-controlled content. The parseDOM.getAttrs handler stores raw… | |
| Aplazada | Media (6.4) | 0.42% | — | 100plugins Open User MAPAI | 24/7/2026 | 24/7/2026 | The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.4.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (5.3) | 0.61% | — | Paymentplugins Payment Plugins FOR StripeAI | 24/7/2026 | 24/7/2026 | The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary… | |
| Aplazada | Crítica (9.1) | 0.41% | — | Project Management BUG AND Issue Tracking PluginAI | 24/7/2026 | 24/7/2026 | The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin… | |
| Aplazada | Alta (8.7) | 0.52% | — | Getgrav Grav API PluginAI | 23/7/2026 | 28/8/2026 | Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted,… | |
| Aplazada | Alta (7.1) | 0.48% | — | Getgrav Grav-plugin-apiAI | 23/7/2026 | 28/8/2026 | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), which strips leading periods but does not neutralize '/' or '..' segments. An… | |
| Aplazada | Alta (8.2) | 0.33% | — | Grav API PluginAI | 23/7/2026 | 28/8/2026 | Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and… |