Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.61% | — | User Registration Using Contact Form 7AI | 17/1/2026 | 17/6/2026 | The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_cf7_form_data' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to retrieve form settings which includes… | |
| Aplazada | Media (6.4) | 0.26% | — | Plugin-planet User Submitted PostsAI | 16/1/2026 | 17/6/2026 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'usp_access' shortcode in all versions up to, and including, 20260110 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Aplazada | Media (5.4) | 0.15% | — | User Registration MembershipAI | 10/1/2026 | 17/6/2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or incorrect nonce validation on the… | |
| Aplazada | Alta (7.5) | 0.33% | — | Latest Registered UsersAI | 7/1/2026 | 17/6/2026 | The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, and including, 1.4. This is due to missing authorization and nonce validation in the rnd_handle_form_submit function hooked to both admin_post_my_simple_form and admin_post_nopriv_my_simple_form… | |
| Aplazada | Media (5.3) | 0.27% | — | WP Front User SubmitAI | 7/1/2026 | 17/6/2026 | The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bfe/v1/revert' REST API endpoint in all versions up to, and including, 5.0.0. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.5) | 0.36% | — | Solwininfotech User Activity LOGAI | 7/1/2026 | 17/6/2026 | The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_login_failed' lacks a capability check and writes failed usernames directly into update_option() calls. This makes it possible for unauthenticated attackers to push… | |
| Aplazada | Media (4.4) | 0.18% | — | Simple User Meta EditorAI | 7/1/2026 | 7/10/2026 | The Simple User Meta Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user meta value field in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Aplazada | Media (5.3) | 0.90% | 💥 Exploit | Wedevs WP User FrontendAI | 2/1/2026 | 17/6/2026 | The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in all versions up to, and including,… | |
| Aplazada | Media (6.5) | 0.16% | — | Wpfactory Maximum Products PER User FOR WoocommerceAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Maximum Products per User for WooCommerce maximum-products-per-user-for-woocommerce allows Stored XSS.This issue affects Maximum Products per User for WooCommerce: from n/a through <= 4.4.3. | |
| Aplazada | Media (6.5) | 0.19% | — | Bainternet User Specific ContentAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bainternet User Specific Content user-specific-content allows DOM-Based XSS.This issue affects User Specific Content: from n/a through <= 1.0.6. | |
| Aplazada | Alta (7.5) | 0.24% | — | Userproplugin UserproAI | 24/12/2025 | 7/10/2026 | Missing Authorization vulnerability in DeluxeThemes Userpro userpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Userpro: from n/a through <= 5.1.9. | |
| Aplazada | Media (4.3) | 0.13% | — | Tikweb Fast User SwitchingAI | 24/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tikweb Management Fast User Switching fast-user-switching allows Cross Site Request Forgery.This issue affects Fast User Switching: from n/a through <= 1.4.10. | |
| Aplazada | Media (4.7) | 0.52% | 💥 Exploit | Plugin-planet User Submitted PostsAI | 24/12/2025 | 7/10/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Jeff Starr User Submitted Posts user-submitted-posts allows Phishing.This issue affects User Submitted Posts: from n/a through <= 20251121. | |
| Aplazada | Alta (7.6) | 0.47% | — | Syedbalkhi User FeedbackAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through <= 1.10.0. | |
| Aplazada | Alta (7.8) | 0.37% | — | Cogview4AIHuggingface DiffusersAI | 23/12/2025 | 17/6/2026 | Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Diffusers. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Crítica (9.8) | 0.37% | — | Flex Store UsersAI | 20/12/2025 | 17/6/2026 | The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUserHandle::signup' and the 'fsSellerRole::add_role_seller' functions not restricting what user roles a user can register with. This makes it possible for unauthenticated… | |
| Analizada | Alta (8.8) | 0.26% | — | Fastapi-users Project Fastapi Users | 19/12/2025 | 17/6/2026 | FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that could link them to the session that initiated the OAuth flow.… | |
| Aplazada | Alta (7.5) | 0.28% | — | Userelements Ultimate Member Widgets FOR ElementorAI | 18/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in UserElements Ultimate Member Widgets for Elementor ultimate-member-widgets-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Ultimate Member Widgets for Elementor: from n/a through <= 2.3. | |
| Analizada | Baja (2.7) | 0.48% | — | Facelessuser Pymdown Extensions | 16/12/2025 | 17/6/2026 | PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a ReDOS bug found within the figure caption extension (`pymdownx.blocks.caption`). In systems that take unchecked user content, this could cause long hanges when processing the data if a malicious… | |
| Aplazada | Media (6.5) | 0.16% | — | Saad Iqbal User Avatar ReloadedAI | 16/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal User Avatar - Reloaded user-avatar-reloaded allows Stored XSS.This issue affects User Avatar - Reloaded: from n/a through <= 1.2.2. | |
| Aplazada | Media (6.4) | 0.29% | — | Wpeverest User RegistrationAI | 15/12/2025 | 7/10/2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode attributes in all versions up to, and including, 4.4.6 due to insufficient input sanitization… | |
| Aplazada | Media (4.3) | 0.24% | — | UserbackAI | 13/12/2025 | 17/6/2026 | The Userback plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the userback_get_json function in all versions up to, and including, 1.0.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract plugin's configuration… | |
| Aplazada | Media (4.3) | 0.17% | — | Resource Library FOR Logged IN UsersAI | 12/12/2025 | 7/10/2026 | The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various unauthorized actions… | |
| Aplazada | Media (6.8) | 0.82% | — | Wpusermanager WP User ManagerAI | 12/12/2025 | 7/10/2026 | The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. This… | |
| Aplazada | Media (6.4) | 0.22% | — | LjusersAI | 12/12/2025 | 7/10/2026 | The LJUsers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'ljuser' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… |