Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.32% | — | Otwthemes Widgetize Pages LightAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Reflected XSS.This issue affects Widgetize Pages Light: from n/a through <= 3.0. | |
| Aplazada | Alta (7.1) | 0.19% | — | Campusexplorer WidgetAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tock Tock Widget tock-widget allows Cross Site Request Forgery.This issue affects Tock Widget: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.35% | — | Simon Show Show Google Analytics WidgetAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simon Show Google Analytics widget show-google-analytics-widget allows Stored XSS.This issue affects Show Google Analytics widget: from n/a through <= 1.5.4. | |
| Modificada | Media (5.4) | 0.30% | — | Brainstormforce Astra Widgets | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.15. | |
| Analizada | Media (4.8) | 0.37% | — | Zephyrwest Category Posts Widget | 7/1/2025 | 17/6/2026 | The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.4) | 0.31% | — | SweepwidgetAI | 7/1/2025 | 17/6/2026 | The SweepWidget Contests, Giveaways, Photo Contests, Competitions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sweepwidget' shortcode in all versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (6.4) | 0.34% | — | Uptodown APK Download WidgetAI | 7/1/2025 | 17/6/2026 | The Uptodown APK Download Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'utd-widget' shortcode in all versions up to, and including, 0.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.28% | — | Theperfectwedding WidgetAI | 7/1/2025 | 17/6/2026 | The ThePerfectWedding.nl Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8. This is due to missing or incorrect nonce validation on the 'update_option' function. This makes it possible for unauthenticated attackers to update the 'tpwKey' option with… | |
| Aplazada | Media (4.4) | 0.26% | — | Toggles Shortcode AND WidgetAI | 7/1/2025 | 17/6/2026 | The Toggles Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 1.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Aplazada | Alta (7.1) | 0.34% | — | Duogeek Custom Dashboard WidgetAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget create-custom-dashboard-widget allows Reflected XSS.This issue affects Custom Dashboard Widget: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.3) | 0.19% | — | Taggbox WidgetAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Taggbox Taggbox taggbox-widget allows Cross Site Request Forgery.This issue affects Taggbox: from n/a through <= 3.3. | |
| Aplazada | Media (4.3) | 0.42% | — | Repuso Social-testimonials-and-reviews-widgetAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso social-testimonials-and-reviews-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social proof testimonials and reviews by Repuso: from n/a through <= 4.97. | |
| Aplazada | Media (5.4) | 0.42% | — | Kishorkhambu WP Custom Widget AreaAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in krozero WP Custom Widget area wp-custom-widget-area allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Widget area: from n/a through <= 1.2.5. | |
| Aplazada | Media (4.3) | 0.35% | — | Marketing Fire Widget OptionsAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widget Options: from n/a through <= 4.0.6.1. | |
| Aplazada | Media (6.4) | 0.35% | — | Slope WidgetsAI | 17/12/2024 | 17/6/2026 | The Slope Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slope-reservations' shortcode in all versions up to, and including, 4.2.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.21% | — | Marcel CL Simple Booking WidgetAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marcel CL Simple Booking Widget simple-booking-widget allows Stored XSS.This issue affects Simple Booking Widget: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.33% | — | Christer F Hello Event Widgets FOR ElementorAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in christer_f Hello Event Widgets For Elementor hello-event-widgets-for-elementor allows DOM-Based XSS.This issue affects Hello Event Widgets For Elementor: from n/a through <= 1.0.2. | |
| Aplazada | Media (5.9) | 0.41% | — | Falselight Cryptocurrency Price WidgetAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in falselight Cryptocurrency Price Widget cryptocurrency-price-widget allows Stored XSS.This issue affects Cryptocurrency Price Widget: from n/a through <= 1.2.3. | |
| Modificada | Alta (8.8) | 0.60% | — | Siteorigin Widgets Bundle | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Greg - SiteOrigin SiteOrigin Widgets Bundle so-widgets-bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SiteOrigin Widgets Bundle: from n/a through <= 1.64.0. | |
| Modificada | Crítica (9.8) | 0.93% | — | Coolplugins Cryptocurrency Widgets | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.6.2. | |
| Aplazada | Media (5.4) | 0.45% | — | Taggbox-widgetAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Taggbox Taggbox taggbox-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Taggbox: from n/a through <= 3.3. | |
| Analizada | Media (4.8) | 0.33% | — | Stellarwp Image Widget | 13/12/2024 | 17/6/2026 | The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.4) | 0.28% | — | Currency Converter Widget PROAI | 12/12/2024 | 17/6/2026 | The Currency Converter Widget ⚡ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'currency-converter-widget-pro' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.7) | 0.41% | — | Aviplugins Login Widget With ShortcodeAI | 9/12/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in aviplugins.com Login Widget With Shortcode login-sidebar-widget allows Phishing.This issue affects Login Widget With Shortcode: from n/a through <= 6.1.2. | |
| Aplazada | Media (6.5) | 0.31% | — | Weboccult Technologies PVT LTD WOT Elementor WidgetsAI | 9/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technologies Pvt Ltd Wot Elementor Widgets wot-elementor-widgets allows DOM-Based XSS.This issue affects Wot Elementor Widgets: from n/a through <= 1.0.1. |