Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.31% | — | Web-settler Custom Login Page StylerAI | 31/1/2025 | 17/6/2026 | The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in , Sign out plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the lps_handle_delete_all_logs(), lps_handle_delete_login_log(), and… | |
| Analizada | Media (6.1) | 0.59% | 💥 Exploit | Tepelstreel A5 Custom Login Page | 31/1/2025 | 17/6/2026 | The A5 Custom Login Page WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.1) | 0.26% | — | Mohsin Khan WP Front END Login AND RegisterAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohsin Khan WP Front-end login and register wp-front-end-login-and-register allows Reflected XSS.This issue affects WP Front-end login and register: from n/a through <= 2.1.0. | |
| Aplazada | Alta (7.1) | 0.37% | — | Limesquare Lime Developer LoginAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in limesquare Lime Developer Login lime-developer-login allows Reflected XSS.This issue affects Lime Developer Login: from n/a through <= 1.4.0. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Favethemes Homey Login RegisterAI | 21/1/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in favethemes Homey Login Register homey-login-register allows Privilege Escalation.This issue affects Homey Login Register: from n/a through <= 2.4.0. | |
| Aplazada | Alta (7.1) | 0.41% | — | Shawfactor LH Login PageAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shawfactor LH Login Page lh-login-page allows Reflected XSS.This issue affects LH Login Page: from n/a through <= 2.14. | |
| Aplazada | Media (5.3) | 0.59% | — | Sanjay Prasad LoginplusAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Sanjay Prasad Loginplus loginplus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Loginplus: from n/a through <= 1.2. | |
| Analizada | Media (5.4) | 0.26% | — | Login Disable Project Login Disable | 9/1/2025 | 17/6/2026 | Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1. | |
| Analizada | Crítica (9.8) | 0.41% | — | Persistent Login Project Persistent Login | 9/1/2025 | 17/6/2026 | Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2. | |
| Aplazada | Alta (7.1) | 0.39% | — | Frankkoenen Ldap Login Password AND Role ManagerAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in frankkoenen ldap_login_password_and_role_manager ldap-login-password-and-role-manager allows Stored XSS.This issue affects ldap_login_password_and_role_manager: from n/a through <= 1.0.12. | |
| Aplazada | Media (5.3) | 0.39% | — | Wpdo Dologin SecurityAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in WPDO DoLogin Security dologin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DoLogin Security: from n/a through <= 3.7.1. | |
| Analizada | Media (5.3) | 0.45% | — | Rems Multi Role Login System | 31/12/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected is an unknown function of the file /endpoint/add-user.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Alta (8.8) | 0.71% | 💥 PoC | Wpbrigade LoginpressAI | 24/12/2024 | 17/6/2026 | The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Temporary admin login access , Rename login , Login customizer, Hide wp-login – Limit Login Attempts – Locked Site plugin for WordPress is vulnerable to privilege escalation due to a missing capability… | |
| Aplazada | Media (5.9) | 0.42% | — | Cortesfrau Better WP Login PageAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cortesfrau Better WP Login Page better-wp-login-page allows Stored XSS.This issue affects Better WP Login Page: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.1) | 0.21% | — | Navdeep WP Login With AjaxAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Navdeep Wp Login with Ajax wp-login-with-ajax allows Stored XSS.This issue affects Wp Login with Ajax: from n/a through <= 0.6. | |
| Aplazada | Media (6.4) | 0.35% | — | Ider LoginAI | 14/12/2024 | 17/6/2026 | The IDer Login for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ider_login_button' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.3) | 0.54% | — | Limitloginattempts Limit Login AttemptsAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wp-buy Limit Login Attempts wp-limit-failed-login-attempts allows SQL Injection.This issue affects Limit Login Attempts: from n/a through <= 5.5. | |
| Aplazada | Media (4.7) | 0.41% | — | Aviplugins Login Widget With ShortcodeAI | 9/12/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in aviplugins.com Login Widget With Shortcode login-sidebar-widget allows Phishing.This issue affects Login Widget With Shortcode: from n/a through <= 6.1.2. | |
| Aplazada | Media (4.3) | 0.43% | — | Netweblogic Login With AjaxAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Marcus (aka @msykes) Login With Ajax login-with-ajax allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login With Ajax: from n/a through <= 4.1. | |
| Aplazada | Media (4.3) | 0.41% | — | Austin Custom Login Custom LoginAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Austin Custom Login custom-login allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login: from n/a through <= 4.1.0. | |
| Aplazada | Media (5.3) | 0.76% | — | Miniorange Wordpress Social Login AND RegisterAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.0. | |
| Aplazada | Baja (3.5) | 0.44% | — | Miniorange Wordpress Social LoginAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.5.14. | |
| Aplazada | Alta (8.1) | 0.65% | — | Login With OTPAI | 6/12/2024 | 17/6/2026 | The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. This is due to the plugin generating too weak OTP, and there’s no attempt or time limit. This makes it possible for unauthenticated attackers to generate and brute force the 6-digit numeric OTP that… | |
| Aplazada | Media (6.4) | 0.40% | — | Login With Vipps AND MobilepayAI | 28/11/2024 | 17/6/2026 | The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'continue-with-vipps' shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (6.9) | 0.65% | — | Phpgurukul User Registration & Login AND User Management System | 27/11/2024 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System 1.0. This affects an unknown part of the file /signup.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… |