Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.8) | 0.22% | — | Bplugins B SliderAI | 28/8/2025 | 25/9/2026 | Missing Authorization vulnerability in bPlugins B Slider b-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Slider: from n/a through <= 1.1.30. | |
| Aplazada | Alta (7.1) | 0.24% | — | Bplugins Tiktok FeedAI | 28/8/2025 | 25/9/2026 | Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Tiktok Feed: from n/a through <= 1.0.21. | |
| Aplazada | Media (4.3) | 0.13% | — | Pluginsandsnippets Simple Page Access RestrictionAI | 27/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction simple-page-access-restriction allows Cross Site Request Forgery.This issue affects Simple Page Access Restriction: from n/a through <= 1.0.32. | |
| Aplazada | Alta (8.8) | 0.43% | — | Pickplugins Post GridAI | 20/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Object Injection.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.11. | |
| Aplazada | Media (5.4) | 0.22% | — | E-plugins WP MembershipAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Membership: from n/a through <= 1.6.3. | |
| Aplazada | Media (6.5) | 0.21% | — | Bplugins B BlocksAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows DOM-Based XSS.This issue affects B Blocks: from n/a through <= 2.0.5. | |
| Aplazada | Media (4.3) | 0.14% | — | Bplugins Button BlockAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bPlugins Button Block button-block allows Cross Site Request Forgery.This issue affects Button Block: from n/a through <= 1.2.0. | |
| Aplazada | Media (6.7) | 0.14% | — | Intel Device Plugins FOR KubernetesAI | 12/8/2025 | 17/6/2026 | Improper access control for some Device Plugins for Kubernetes software maintained by Intel before version 0.32.0 may allow a privileged user to potentially enable denial of service via local access. | |
| Analizada | Media (5.3) | 0.94% | 💥 Exploit | Fullworksplugins Stop User Enumeration | 17/7/2025 | 17/6/2026 | The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path. | |
| Aplazada | Media (6.5) | 0.18% | — | Bplugins Lightbox BlockAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins LightBox Block lightbox-block allows Stored XSS.This issue affects LightBox Block: from n/a through <= 1.1.30. | |
| Aplazada | Media (4.3) | 0.14% | — | Toast Plugins AnimatorAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Animator scroll-triggered-animations allows Cross Site Request Forgery.This issue affects Animator: from n/a through <= 3.0.16. | |
| Aplazada | Media (6.6) | 0.55% | — | HT Plugins HT Contact Form 7AI | 16/7/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows PHP Local File Inclusion.This issue affects HT Contact Form 7: from n/a through <= 2.0.0. | |
| Analizada | Media (5.4) | 0.23% | — | Fooplugins Foogallery | 11/7/2025 | 17/6/2026 | The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to insufficient input sanitization and… | |
| Aplazada | Media (6.5) | 0.30% | — | Aviplugins WP Register Profile With ShortcodeAI | 11/7/2025 | 17/6/2026 | The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'rp_user_data' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data from user meta… | |
| Analizada | Media (5.4) | 0.18% | — | Fooplugins Foobox | 8/7/2025 | 17/6/2026 | The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alternative texts in all versions up to, and including, 2.7.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.19% | — | Bplugins Video Gallery BlockAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gallery Block video-gallery-block allows Stored XSS.This issue affects Video Gallery Block: from n/a through <= 1.1.0. | |
| Analizada | Media (5.4) | 0.26% | — | Pwrplugins Powerfolio | 4/7/2025 | 17/6/2026 | The Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS Attributes of Plugin's widgets in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.25% | — | Pwrplugins Magic Buttons FOR Elementor | 2/7/2025 | 17/6/2026 | The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on the 'icon' user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.24% | — | Pwrplugins Magic Buttons FOR Elementor | 2/7/2025 | 17/6/2026 | The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on the 'text' user supplied attribute. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.23% | — | Aviplugins Thumbnail EditorAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Thumbnail Editor thumbnail-editor allows Stored XSS.This issue affects Thumbnail Editor: from n/a through <= 2.3.3. | |
| Aplazada | Media (5.4) | 0.15% | — | Pluginscafe Address Autocomplete VIA Google FOR Gravity FormsAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PluginsCafe Address Autocomplete via Google for Gravity Forms gf-google-address-autocomplete allows Cross Site Request Forgery.This issue affects Address Autocomplete via Google for Gravity Forms: from n/a through <= 1.3.4. | |
| Aplazada | Media (6.5) | 0.24% | — | HT Plugins HT Mega Absolute Addons FOR WpbakeryAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega – Absolute Addons for WPBakery Page Builder ht-mega-for-wpbakery allows Stored XSS.This issue affects HT Mega – Absolute Addons for WPBakery Page Builder: from n/a through <= 1.0.8. | |
| Aplazada | Media (6.5) | 0.23% | — | Prowcplugins Related Products Manager FOR WoocommerceAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProWCPlugins Related Products Manager for WooCommerce related-products-manager-woocommerce allows DOM-Based XSS.This issue affects Related Products Manager for WooCommerce: from n/a through <= 1.6.2. | |
| Aplazada | Media (6.5) | 0.23% | — | Aviplugins WP Register Profile With ShortcodeAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com WP Register Profile With Shortcode wp-register-profile-with-shortcode allows Stored XSS.This issue affects WP Register Profile With Shortcode: from n/a through <= 3.6.3. | |
| Aplazada | Media (4.3) | 0.26% | — | Grandplugins Image Sizes ControllerAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes image-sizes-controller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a… |