Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.0% | — | Profilepress User Registration, Login Form, User Profile & Membership | 13/12/2021 | 17/6/2026 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (8.8) | 1.7% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 13/9/2021 | 17/6/2026 | The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages. | |
| Modificada | Alta (8.8) | 2.0% | — | Strangerstudios Paid Memberships PRO | 18/3/2021 | 17/6/2026 | SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.2% | — | Strangerstudios Paid Memberships PRO | 20/5/2020 | 17/6/2026 | SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5.4) | 2.8% | 💥 Exploit | E-plugins WP Membership | 6/1/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for… | |
| Modificada | Alta (8.8) | 2.0% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload. | |
| Modificada | Alta (8.8) | 1.7% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action. | |
| Modificada | Alta (8.8) | 0.67% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php. | |
| Modificada | Media (5.4) | 0.71% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter. | |
| Modificada | Media (5.4) | 1.2% | — | Usersultra Users Ultra Membership | 20/9/2019 | 17/6/2026 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter. | |
| Modificada | Media (6.1) | 0.95% | — | Ithemes Membership | 28/8/2019 | 17/6/2026 | Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |
| Modificada | Alta (8.8) | 0.70% | — | Simple-membership-plugin Simple Membership | 14/8/2019 | 17/6/2026 | The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues. | |
| Modificada | Media (6.1) | 0.92% | — | Simple-membership-plugin Simple Membership | 12/8/2019 | 17/6/2026 | The simple-membership plugin before 3.5.7 for WordPress has XSS. | |
| Modificada | Alta (8.8) | 3.1% | 💥 Exploit | Simple-membership-plugin Simple Membership | 28/7/2019 | 17/6/2026 | The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section. | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.6% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | Ultimatemember User Profile & Membership | 14/5/2018 | 17/6/2026 | Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.97% | — | Auroradao Idex Membership | 3/5/2018 | 17/6/2026 | The Owned smart contract implementation for Aurora IDEX Membership (IDXM), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. A new owner can subsequently modify variables. | |
| Modificada | Media (4.8) | 0.62% | — | Ultimatemember User Profile & Membership | 23/4/2018 | 17/6/2026 | Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page. | |
| Modificada | Alta (8.8) | 0.67% | — | Ultimatemember User Profile & Membership | 23/4/2018 | 17/6/2026 | The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 Exploit | Jextn Membership | 2/2/2018 | 17/6/2026 | SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request. | |
| Modificada | Media (6.1) | 2.1% | — | Strangerstudios Paid Memberships PRO | 23/10/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to… | |
| Modificada | Crítica (9.8) | 2.3% | — | Ontraport Membership Simplified | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete_media function. |