Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.19% | — | AI Auto Tool Content Writing AssistantAI | 4/11/2025 | 17/6/2026 | The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_post_data() function in versions 2.0.7 to 2.2.6. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.54% | — | Restful Content SyndicationAI | 1/11/2025 | 17/6/2026 | The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ingest_image() function in versions 1.1.0 to 1.5.0. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected… | |
| Aplazada | Media (4.3) | 0.25% | — | Evergreencontentposter Evergreen Content PosterAI | 29/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Evergreen Content Poster: from n/a through <= 1.4.5. | |
| Aplazada | Media (4.3) | 0.14% | — | Clifton Griffin Simple Content Templates FOR Blog Posts AND PagesAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Clifton Griffin Simple Content Templates for Blog Posts & Pages simple-post-template allows Cross Site Request Forgery.This issue affects Simple Content Templates for Blog Posts & Pages: from n/a through <= 2.2.61. | |
| Aplazada | Media (6.5) | 0.33% | — | Neliosoftware Nelio ContentAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Nelio Software Nelio Content nelio-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nelio Content: from n/a through <= 4.0.5. | |
| Aplazada | Media (6.5) | 0.20% | — | Rockcontent Rock ConvertAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Content Rock Convert rock-convert allows Stored XSS.This issue affects Rock Convert: from n/a through <= 3.0.1. | |
| Aplazada | Media (4.3) | 0.13% | — | Disable Content Editor FOR Specific TemplateAI | 24/10/2025 | 17/6/2026 | The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing nonce validation on template configuration updates. This makes it possible for unauthenticated attackers to add or delete template… | |
| Aplazada | Alta (7.1) | 0.30% | — | Jonatan Jumbert Wpcode Content RatioAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonatan Jumbert WPCode Content Ratio wpcode-content-ratio allows Reflected XSS.This issue affects WPCode Content Ratio: from n/a through <= 2.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Evergreencontentposter Evergreen Content PosterAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster allows Cross Site Request Forgery.This issue affects Evergreen Content Poster: from n/a through <= 1.4.5. | |
| Aplazada | Media (5.3) | 0.33% | — | Content WriterAI | 15/10/2025 | 17/6/2026 | The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.8 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files. | |
| Aplazada | Alta (7.2) | 0.29% | — | Find AND Replace ContentAI | 15/10/2025 | 17/6/2026 | The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scripting and Arbitrary Content Replacement due to a missing capability check on the far_admin_ajax_fun() function in all versions up to, and including, 1.1. This makes it possible for unauthenticated… | |
| Analizada | Media (5.3) | 0.31% | — | IBM Content Navigator | 14/10/2025 | 17/6/2026 | IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified. | |
| Aplazada | Media (6.5) | 0.30% | 💥 PoC | Wpexpertdeveloper WP Private Content PlusAI | 13/10/2025 | 17/6/2026 | The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually… | |
| Aplazada | Media (4.3) | 0.17% | — | Contentmx Content PublisherAI | 3/10/2025 | 17/6/2026 | The ContentMX Content Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the cmx_activate_connection function. This makes it possible for unauthenticated attackers to bind their own ContentMX… | |
| Aplazada | Alta (8.5) | 0.26% | — | Lambertgroup All-in-one Content SliderAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Content Slider all-in-one-contentSlider allows Blind SQL Injection.This issue affects LambertGroup - AllInOne - Content Slider: from n/a through <= 3.8. | |
| Aplazada | Alta (7.7) | 0.42% | — | Seatheme BM Content BuilderAI | 26/9/2025 | 30/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder bm-builder allows Path Traversal.This issue affects BM Content Builder: from n/a through < 3.16.3.3. | |
| Aplazada | Alta (7.1) | 0.13% | — | Shankaranand Maurya WP Content ProtectionAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection wp-content-protection allows Stored XSS.This issue affects WP Content Protection: from n/a through <= 1.3. | |
| Aplazada | Media (6.5) | 0.21% | — | JSM File GET Contents ShortcodeAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JS Morisset JSM file_get_contents() Shortcode wp-file-get-contents allows Stored XSS.This issue affects JSM file_get_contents() Shortcode: from n/a through <= 2.7.1. | |
| Aplazada | Baja (3.8) | 0.34% | — | Alex Content Mask Content MaskAI | 22/9/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Alex Content Mask content-mask allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Content Mask: from n/a through <= 1.8.5.3. | |
| Aplazada | Media (6.4) | 0.21% | — | Alex Content Mask Content MaskAI | 22/9/2025 | 30/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in Alex Content Mask content-mask allows Server Side Request Forgery.This issue affects Content Mask: from n/a through <= 1.8.5.2. | |
| Aplazada | Media (5.8) | 0.24% | — | Vignette Content ManagementAI | 11/9/2025 | 17/6/2026 | In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to download unprotected files from the server if the filenames are known. | |
| Aplazada | Alta (7.6) | 0.28% | — | Presstigers ZIP Code Based Content ProtectionAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection zip-code-based-content-protection allows SQL Injection.This issue affects ZIP Code Based Content Protection: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.4) | 0.24% | — | Contentviewspro Content ViewsAI | 6/9/2025 | 17/6/2026 | The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid and List widgets in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.24% | — | Kaizencoders Table OF ContentAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Table of content content-table allows Stored XSS.This issue affects Table of content: from n/a through <= 1.5.3.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Digitalcourt Boxed ContentAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DigitalCourt Boxed Content boxed-content allows Stored XSS.This issue affects Boxed Content: from n/a through <= 1.0. |