Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
721 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Sistemasbebetter Bebetter Social IconsAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sistemasBebetter BeBetter Social Icons bebetter-social-icons allows DOM-Based XSS.This issue affects BeBetter Social Icons: from n/a through <= 2.7. | |
| Aplazada | Media (6.5) | 0.32% | — | Riponshah Social ButtonAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in riponshah Social button social-button allows Stored XSS.This issue affects Social button: from n/a through <= 1.3. | |
| Aplazada | Media (6.5) | 0.32% | — | Leroysabrina Simple Social Share BlockAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leroysabrina Simple Social Share Block simple-social-share-block allows Stored XSS.This issue affects Simple Social Share Block: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.43% | — | Pluginops Social LockerAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Social Locker social-locker-content allows Stored XSS.This issue affects Social Locker: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.37% | — | Nomaniplex Easy Social SharebarAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nomaniplex Easy Social Sharebar easy-social-sharebar allows Stored XSS.This issue affects Easy Social Sharebar: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Z.com BY GMO GMO Social ConnectionAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Z.com byGMO GMO Social Connection gmo-social-connection allows Cross-Site Scripting (XSS).This issue affects GMO Social Connection: from n/a through <= 1.2. | |
| Aplazada | Alta (7.1) | 0.20% | — | MD Eftakhairul Islam Sticky Social BARAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Md Eftakhairul Islam Sticky Social Bar sticky-social-bar allows Cross Site Request Forgery.This issue affects Sticky Social Bar: from n/a through <= 2.0. | |
| Aplazada | Media (6.4) | 0.43% | — | Social Proof Testimonial SliderAI | 13/11/2024 | 17/6/2026 | The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spslider-block shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (8.1) | 0.63% | — | Heateor Super Socializer | 6/11/2024 | 17/6/2026 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for… | |
| Analizada | Alta (8.1) | 0.52% | — | Heateor Social Login | 6/11/2024 | 17/6/2026 | The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user… | |
| Analizada | Alta (8.1) | 0.54% | — | Wpwebelite Woocommerce Social Login | 5/11/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Aplazada | Media (4.3) | 0.39% | — | Creativemotion Social Slider FeedAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in creativemotion Social Slider Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Slider Feed: from n/a through 2.2.2. | |
| Aplazada | Media (6.5) | 0.44% | — | Quadlayers WP Social Feed GalleryAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in QuadLayers WP Social Feed Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Social Feed Gallery: from n/a through 4.3.9. | |
| Aplazada | Crítica (9.8) | 0.78% | — | Wpmet WP Social Login AND Register Social CounterAI | 26/10/2024 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any… | |
| Analizada | Media (6.1) | 0.32% | — | 10web Social Post Feed | 25/10/2024 | 17/6/2026 | The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute… | |
| Modificada | Alta (8.8) | 0.21% | — | Wpwebinfotech Social Auto Poster | 20/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpweb Social Auto Poster social-auto-poster allows Cross Site Request Forgery.This issue affects Social Auto Poster: from n/a through <= 5.3.15. | |
| Modificada | Alta (8.8) | 0.44% | — | Acespritech Social Link Groups | 20/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acespritech Social Link Groups social-link-groups allows Blind SQL Injection.This issue affects Social Link Groups: from n/a through <= 1.1.0. | |
| Analizada | Media (6.1) | 0.40% | — | Maxfoundry Social Share Buttons | 19/10/2024 | 17/6/2026 | The WordPress Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.19. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (6.1) | 0.34% | — | Themeinwp Social Share With Floating BAR | 18/10/2024 | 17/6/2026 | The Social Share With Floating Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Nextend Social Login PROAI | 16/10/2024 | 17/6/2026 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Analizada | Media (6.1) | 17% | 💥 Exploit | Heateor Sassy Social Share | 16/10/2024 | 17/6/2026 | The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Analizada | Media (6.5) | 0.50% | — | Nextscripts Social Networks Auto Poster | 16/10/2024 | 17/6/2026 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform… | |
| Analizada | Media (5.4) | 0.26% | — | Ibericode Social Sharing | 12/10/2024 | 17/6/2026 | The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.1) | 0.31% | — | Idiom Easy Social Share Buttons | 10/10/2024 | 17/6/2026 | The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (6.1) | 0.33% | — | Wpwebinfotech Social Auto Poster | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb Social Auto Poster social-auto-poster allows Reflected XSS.This issue affects Social Auto Poster: from n/a through <= 5.3.15. |