Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.39% | — | Themeisle RSS Aggregator BY Feedzy | 20/10/2023 | 17/6/2026 | The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible for unauthenticated attackers to update post meta via a forged… | |
| Modificada | Media (6.1) | 0.33% | — | Arrowplugins Social Feed | 17/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins Social Feed | Custom Feed for Social Media Networks plugin <= 2.2.0 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Feed Statistics Project Feed Statistics | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Christopher Finke Feed Statistics plugin <= 4.1 versions. | |
| Modificada | Alta (8.8) | 0.44% | — | Mekshq Meks Audio PlayerMekshq Meks Easy ADS WidgetMekshq Meks Easy MapsMekshq Meks Easy Photo Feed Widget+6 | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the… | |
| Modificada | Media (5.4) | 0.38% | — | Arrowplugins THE Awesome Feed | 2/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2.5 versions. | |
| Analizada | Media (6.1) | 0.56% | — | Monsterinsights Userfeedback | 29/9/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.7 versions. | |
| Modificada | Crítica (9.8) | 41% | 💥 Exploit | Mooveagency Import XML AND RSS Feeds | 25/9/2023 | 17/6/2026 | The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42)… | |
| Modificada | Alta (7.2) | 2.0% | 💥 PoC | Mooveagency Import XML AND RSS Feeds | 25/9/2023 | 17/6/2026 | The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution. | |
| Modificada | Crítica (9.8) | 0.81% | — | Blmodules Xmlfeeds PRO | 15/9/2023 | 17/6/2026 | Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds(). | |
| Modificada | Media (5.4) | 0.55% | — | Smashballoon Feeds FOR Youtube | 14/9/2023 | 17/6/2026 | The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Media (4.8) | 0.40% | — | Stormconsultancy Oauth Twitter Feed FOR Developers | 1/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy (Storm Consultancy) oAuth Twitter Feed for Developers plugin <= 2.3.0 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Web-settler Image Social Feed | 1/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Image Social Feed plugin <= 1.7.6 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Devbuddy Twitter Feed | 25/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eji Osigwe DevBuddy Twitter Feed plugin <= 4.0.0 versions. | |
| Modificada | Media (4.3) | 0.61% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+6 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.5) | 0.69% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+7 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,… | |
| Modificada | Media (5.5) | 0.17% | — | THM Feedbacksystem | 13/7/2023 | 17/6/2026 | Feedbacksystem is a personalized feedback system for students using artificial intelligence. Passwords of users using LDAP login are stored in clear text in the database. The LDAP users password is passed unencrypted in the LoginController.scala and stored in the database when logging in for the first time. Users… | |
| Modificada | Media (4.3) | 0.38% | — | Exportfeed Woocommerce Etsy Integration | 12/7/2023 | 17/6/2026 | The WooCommerce Etsy Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.1. This is due to missing or incorrect nonce validation on the etcpf_delete_feed() function. This makes it possible for unauthenticated attackers to delete an export feed via a forged… | |
| Modificada | Alta (8.8) | 0.32% | — | Hasthemes HT Feed | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Feed plugin <= 1.2.7 versions. | |
| Modificada | Media (4.3) | 0.48% | — | Slickremix Feed Them Social | 1/7/2023 | 17/6/2026 | The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the my_fts_fb_load_more() function. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (6.1) | 0.46% | — | 10web Social Post Feed | 5/6/2023 | 17/6/2026 | The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (4.8) | 0.47% | — | ADD TO Feedly Project ADD TO Feedly | 30/5/2023 | 17/6/2026 | The Add to Feedly WordPress plugin through 1.2.11 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8.8) | 0.25% | — | Smashballoon Custom Twitter Feeds | 29/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Slickremix Feed Them Social | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SlickRemix Feed Them Social plugin <= 3.0.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Tipsandtricks-hq Category Specific RSS Feed Subscription | 12/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Te-st Yandex.news Feed BY Teplitsa | 8/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa Yandex.News Feed by Teplitsa plugin <= 1.12.5 versions. |