Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Idnovate Popup Module (ON Entering, Exit Popup, ADD Product) AND Newsletter | 12/4/2023 | 17/6/2026 | Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups(). | |
| Modificada | Media (4.8) | 0.39% | — | Wpdevart Download Image AND Video Lightbox, Image Popup | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart Image and Video Lightbox, Image PopUp plugin <= 2.1.5 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Timersys WP Popups | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Timersys WP Popups – WordPress Popup plugin <= 2.1.4.8 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Wpdevart Youtube Embed, Playlist AND Popup | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart YouTube Embed, Playlist and Popup by WpDevArt plugin <= 2.6.3 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Linksoftwarellc WP Terms Popup | 6/4/2023 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Link Software LLC WP Terms Popup plugin <= 2.6.0 versions. | |
| Modificada | Media (4.8) | 0.42% | — | Mrdigital Simple Image Popup | 29/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mr Digital Simple Image Popup plugin <= 1.3.6 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Essentialplugin Popup Anything | 29/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions. | |
| Modificada | Alta (8.8) | 0.87% | — | Accesspressthemes WP Popup Banners | 22/3/2023 | 17/6/2026 | The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action. | |
| Modificada | Media (6.5) | 0.94% | — | WP Popup Banners Project WP Popup Banners | 17/3/2023 | 17/6/2026 | The WP Popup Banners plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' parameter in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers… | |
| Modificada | Media (6.1) | 0.61% | — | Woo-popup Project Woo-popup | 6/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in woo-popup Plugin up to 1.2.2 on WordPress. This affects an unknown part of the file admin/class-woo-popup-admin.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.3.0 is able to address… | |
| Modificada | Media (5.4) | 0.47% | — | Timersys WP Popups | 23/1/2023 | 17/6/2026 | The WP Popups WordPress plugin before 2.1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Media (5.4) | 0.53% | — | Code-atlantic Popup Maker | 2/1/2023 | 17/6/2026 | The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.56% | — | Code-atlantic Popup Maker | 2/1/2023 | 17/6/2026 | The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.3) | 0.29% | — | Popup Manager Project Popup Manager | 19/12/2022 | 17/6/2026 | The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well | |
| Modificada | Media (4.3) | 0.28% | — | Popup Manager Project Popup Manager | 19/12/2022 | 17/6/2026 | The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them | |
| Modificada | Media (4.8) | 0.66% | — | Code-atlantic Popup Maker | 21/11/2022 | 17/6/2026 | The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins | |
| Modificada | Crítica (9.8) | 1.2% | — | Newsletter Subscribe (popup + Regular Module) Project Newsletter Subscribe (popup + Regular Module) | 12/10/2022 | 17/6/2026 | OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter. | |
| Modificada | Media (4.3) | 0.32% | — | Themehunk WP Popup Builder | 26/9/2022 | 17/6/2026 | The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup | |
| Modificada | Media (6.1) | 0.61% | — | Themehunk WP Popup Builder | 26/9/2022 | 17/6/2026 | The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (8.8) | 0.98% | — | Mypopups Pop-up | 9/9/2022 | 17/6/2026 | Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress. | |
| Modificada | Media (4.8) | 0.61% | — | Timersys Popups | 1/8/2022 | 17/6/2026 | The WordPress Popup WordPress plugin through 1.9.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.66% | — | Essentialplugin Popup Anything | 25/7/2022 | 17/6/2026 | The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.3) | 0.51% | 💥 Exploit | Sygnoos Popup Builder | 22/7/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings. | |
| Modificada | Media (4.3) | 0.33% | — | Sygnoos Popup Builder | 21/7/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change. | |
| Modificada | Media (4.8) | 0.59% | — | Sygnoos Popup Builder | 11/7/2022 | 17/6/2026 | The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed |