Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

293 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.0%💥 ExploitIdnovate Popup Module (ON Entering, Exit Popup, ADD Product) AND Newsletter12/4/202317/6/2026
Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().
ModificadaMedia (4.8)0.39%—Wpdevart Download Image AND Video Lightbox, Image Popup6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart Image and Video Lightbox, Image PopUp plugin <= 2.1.5 versions.
ModificadaMedia (5.4)0.39%—Timersys WP Popups6/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Timersys WP Popups – WordPress Popup plugin <= 2.1.4.8 versions.
ModificadaMedia (4.8)0.39%—Wpdevart Youtube Embed, Playlist AND Popup6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart YouTube Embed, Playlist and Popup by WpDevArt plugin <= 2.6.3 versions.
ModificadaMedia (4.8)0.39%—Linksoftwarellc WP Terms Popup6/4/202317/6/2026
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Link Software LLC WP Terms Popup plugin <= 2.6.0 versions.
ModificadaMedia (4.8)0.42%—Mrdigital Simple Image Popup29/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mr Digital Simple Image Popup plugin <= 1.3.6 versions.
ModificadaAlta (8.8)0.26%—Essentialplugin Popup Anything29/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions.
ModificadaAlta (8.8)0.87%—Accesspressthemes WP Popup Banners22/3/202317/6/2026
The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action.
ModificadaMedia (6.5)0.94%—WP Popup Banners Project WP Popup Banners17/3/202317/6/2026
The WP Popup Banners plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' parameter in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers…
ModificadaMedia (6.1)0.61%—Woo-popup Project Woo-popup6/3/202317/6/2026
A vulnerability classified as problematic has been found in woo-popup Plugin up to 1.2.2 on WordPress. This affects an unknown part of the file admin/class-woo-popup-admin.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.3.0 is able to address…
ModificadaMedia (5.4)0.47%—Timersys WP Popups23/1/202317/6/2026
The WP Popups WordPress plugin before 2.1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaMedia (5.4)0.53%—Code-atlantic Popup Maker2/1/202317/6/2026
The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.56%—Code-atlantic Popup Maker2/1/202317/6/2026
The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
ModificadaMedia (4.3)0.29%—Popup Manager Project Popup Manager19/12/202217/6/2026
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well
ModificadaMedia (4.3)0.28%—Popup Manager Project Popup Manager19/12/202217/6/2026
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them
ModificadaMedia (4.8)0.66%—Code-atlantic Popup Maker21/11/202217/6/2026
The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins
ModificadaCrítica (9.8)1.2%—Newsletter Subscribe (popup + Regular Module) Project Newsletter Subscribe (popup + Regular Module)12/10/202217/6/2026
OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter.
ModificadaMedia (4.3)0.32%—Themehunk WP Popup Builder26/9/202217/6/2026
The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup
ModificadaMedia (6.1)0.61%—Themehunk WP Popup Builder26/9/202217/6/2026
The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (8.8)0.98%—Mypopups Pop-up9/9/202217/6/2026
Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress.
ModificadaMedia (4.8)0.61%—Timersys Popups1/8/202217/6/2026
The WordPress Popup WordPress plugin through 1.9.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.1)0.66%—Essentialplugin Popup Anything25/7/202217/6/2026
The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (4.3)0.51%💥 ExploitSygnoos Popup Builder22/7/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.
ModificadaMedia (4.3)0.33%—Sygnoos Popup Builder21/7/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change.
ModificadaMedia (4.8)0.59%—Sygnoos Popup Builder11/7/202217/6/2026
The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed
Orbitaley — Vulnerabilidades