Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.41% | — | Properfraction Profilepress | 3/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions. | |
| Modificada | Media (5.4) | 0.41% | — | Properfraction Profilepress | 3/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions. | |
| Modificada | Alta (8.1) | 0.99% | — | Cozmoslabs Profile Builder | 27/4/2023 | 17/6/2026 | The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function… | |
| Modificada | Media (4.8) | 0.42% | — | Properfraction Profilepress | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Properfraction Profilepress | 29/3/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin <= 4.5.3 versions. | |
| Modificada | Alta (8.8) | 0.82% | — | Metagauss Profilegrid | 20/3/2023 | 17/6/2026 | The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones. | |
| Modificada | Media (5.4) | 0.40% | — | Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms | 16/3/2023 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions. | |
| Modificada | Media (6.5) | 0.77% | — | Cozmoslabs Profile Builder | 14/2/2023 | 17/6/2026 | The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This… | |
| Modificada | Media (5.4) | 0.55% | — | Paidmembershipspro Custom User Profile Fields FOR User Registration | 30/1/2023 | 17/6/2026 | The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against… | |
| Modificada | Media (4.8) | 0.66% | — | Properfraction Profilepress | 23/12/2022 | 17/6/2026 | The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (4.8) | 0.71% | — | Properfraction Profilepress | 23/12/2022 | 17/6/2026 | The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_url’ parameter in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Modificada | Alta (8.8) | 0.70% | — | Metagauss Profilegrid | 17/11/2022 | 17/6/2026 | Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress. | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Metagauss Profilegrid | 14/11/2022 | 17/6/2026 | The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Vtune Profiler | 11/11/2022 | 17/6/2026 | Uncontrolled search path in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.3) | 0.27% | — | Cozmoslabs Profile Builder | 11/10/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on. | |
| Modificada | Alta (7.8) | 0.27% | — | Intel Vtune Profiler | 18/8/2022 | 17/6/2026 | Uncontrolled search path elements in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 2.3% | — | User-meta User Meta User Profile Builder AND User Management | 8/6/2022 | 17/6/2026 | The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads | |
| Modificada | Media (4.8) | 0.59% | — | User-meta User Meta User Profile Builder AND User Management | 30/5/2022 | 17/6/2026 | The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (4.8) | 0.60% | — | Wpsheeteditor Bulk Edit AND Create User Profiles - WP Sheet Editor | 16/5/2022 | 17/6/2026 | The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.8) | 0.65% | — | Cozmoslabs Profile Builder | 4/4/2022 | 17/6/2026 | The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (6.1) | 2.7% | 💥 Exploit | Cozmoslabs Profile Builder | 24/2/2022 | 17/6/2026 | The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes… | |
| Modificada | Media (5.4) | 0.60% | — | Fivestarplugins Five Star Business Profile AND Schema | 21/2/2022 | 17/6/2026 | The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of… | |
| Modificada | Media (5.4) | 0.90% | — | Metagauss Profilegrid | 18/1/2022 | 17/6/2026 | The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user… | |
| Modificada | Media (6.1) | 1.0% | — | Profilepress User Registration, Login Form, User Profile & Membership | 13/12/2021 | 17/6/2026 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 1.0% | — | Profilepress User Registration, Login Form, User Profile & Membership | 13/12/2021 | 17/6/2026 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue |