Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.28%—Simple-membership-plugin Simple Membership24/1/202417/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.4.1.
ModificadaCrítica (9.8)1.00%—Millionclues Admin CSS MUDeano AMP ToolboxUnihost Confirm DataAgence-press CSS Adder+1119/1/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long…
ModificadaMedia (6.1)0.38%—Simple-membership-plugin Simple Membership11/1/202417/6/2026
The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ parameter in all versions up to, and including, 4.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
ModificadaMedia (5.3)0.51%—Strangerstudios Paid Memberships PRO11/1/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up…
ModificadaMedia (6.5)0.44%—Butlerblog Wp-members4/1/202417/6/2026
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including user emails,…
ModificadaMedia (5.4)0.61%—Carmelogarcia Intern Membership Management System28/12/202317/6/2026
A vulnerability was found in code-projects Intern Membership Management System 2.0. It has been classified as problematic. This affects an unknown part of the file /user_registration/ of the component User Registration. The manipulation of the argument userName/firstName/lastName/userEmail with the input…
ModificadaCrítica (9.8)0.72%—Carmelogarcia Intern Membership Management System28/12/202317/6/2026
A vulnerability was found in code-projects Intern Membership Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user_registration/ of the component User Registration. The manipulation of the argument userName leads to sql injection. The exploit has been…
ModificadaMedia (6.1)0.46%—Simple-membership-plugin Simple Membership19/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp.Insider Simple Membership allows Reflected XSS.This issue affects Simple Membership: from n/a through 4.3.8.
ModificadaAlta (8.8)51%—Strangerstudios Paid Memberships PRO18/11/202317/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or…
ModificadaMedia (4.8)0.39%—Dazzlersoft Team Members Showcase16/11/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dazzlersoft Team Members Showcase plugin <= 1.3.4 versions.
ModificadaAlta (7.5)0.69%—Memberscard Project Memberscard14/11/202317/6/2026
An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
ModificadaAlta (8.2)0.58%—Linecorp Fukunaga Memberscard25/10/202317/6/2026
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
ModificadaMedia (4.3)0.39%—Strangerstudios Paid Memberships PRO20/10/202317/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted they…
ModificadaCrítica (9.8)0.82%—Razormist Simple Membership System29/9/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Membership System 1.0. This issue affects some unknown processing of the file group_validator.php. The manipulation of the argument club_id leads to sql injection. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (6.5)0.45%—Kokoroe Members Card Project Kokoroe Members Card20/9/202317/6/2026
An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send crafted messages.
ModificadaMedia (6.5)0.46%—THE B Members Card Project THE B Members Card18/9/20239/7/2026
An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
ModificadaAlta (7.5)0.61%—Razormist Simple Membership System17/9/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulnerability is an unknown functionality of the file club_validator.php. The manipulation of the argument club leads to sql injection. The attack can be launched remotely. The exploit has been disclosed…
ModificadaAlta (7.5)0.61%—Razormist Simple Membership System9/9/202317/6/2026
A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been rated as critical. This issue affects some unknown processing of the file delete_member.php. The manipulation of the argument mem_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.74%—Razormist Simple Membership System9/9/202317/6/2026
A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file account_edit_query.php. The manipulation of the argument admin_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…
ModificadaAlta (7.5)0.60%—Razormist Simple Membership System8/9/202317/6/2026
A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been classified as critical. This affects an unknown part of the file club_edit_query.php. The manipulation of the argument club_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaMedia (6.1)0.57%—Simple-membership-plugin Simple Membership6/9/202317/6/2026
The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. Using this vulnerability, unauthenticated attackers could inject arbitrary web scripts into pages…
ModificadaMedia (4.8)0.36%—Minorange Wordpress Yourmembership Single Sign-on1/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange YourMembership Single Sign On – YM SSO Login plugin <= 1.1.3 versions.
ModificadaMedia (4.3)0.34%—Samsung Members10/8/202317/6/2026
Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information.
ModificadaMedia (4.3)0.50%—Butlerblog Wp-members12/7/202317/6/2026
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on…
ModificadaMedia (4.8)0.37%—Ntzapps CRM Memberships23/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NTZApps CRM Memberships plugin <= 1.6 versions.
Orbitaley — Vulnerabilidades