Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.1% | 💥 PoC | Spicethemes Newsblogger | 1/5/2025 | 17/6/2026 | The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up to, and including, 0.2.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload… | |
| Aplazada | Media (5.9) | 0.22% | — | Wpdiscover Blog Manager WPAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Blog Manager WP blog-manager-wp allows Stored XSS.This issue affects Blog Manager WP: from n/a through <= 1.0.5. | |
| Aplazada | Alta (7.1) | 0.15% | — | Pham Thanh Call NOW PHT BlogAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pham Thanh Call Now PHT Blog call-now-coccoc-pht-blog allows Stored XSS.This issue affects Call Now PHT Blog: from n/a through <= 2.4.1. | |
| Analizada | Crítica (9.1) | 0.40% | — | Dogukanurker Flaskblog | 21/4/2025 | 17/6/2026 | Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input. | |
| Analizada | Media (6.4) | 0.22% | — | Dogukanurker Flaskblog | 21/4/2025 | 17/6/2026 | Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request. | |
| Analizada | Media (6.1) | 0.24% | — | Dogukanurker Flaskblog | 21/4/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent parameter at /createpost. | |
| Analizada | Alta (7.6) | 0.42% | — | Appleple A-blogcms | 17/4/2025 | 17/6/2026 | An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path. | |
| Analizada | Media (6.5) | 0.21% | — | Dogukanurker Flaskblog | 17/4/2025 | 17/6/2026 | An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request. | |
| Aplazada | Media (6.5) | 0.27% | — | Graphthemes Glossy BlogAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphthemes Glossy Blog glossy-blog allows Stored XSS.This issue affects Glossy Blog: from n/a through <= 1.0.3. | |
| Analizada | Alta (8.8) | 0.75% | — | Perfreeblog | 15/4/2025 | 17/6/2026 | In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them. | |
| Analizada | Media (4.8) | 0.27% | — | Perfreeblog | 15/4/2025 | 17/6/2026 | Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code. | |
| Aplazada | Alta (7.5) | 0.36% | — | Crocoblock JetblogAI | 15/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetBlog: from n/a through <= 2.4.3. | |
| Aplazada | Media (6.5) | 0.22% | — | Crocoblock JetblogAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows DOM-Based XSS.This issue affects JetBlog: from n/a through <= 2.4.3. | |
| Analizada | Media (5.3) | 0.56% | — | Zhenfeng13 My-blog-layui | 14/4/2025 | 17/6/2026 | A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerability affects the function Upload of the file /admin/upload/authorImg/. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.1) | 0.40% | — | Zhenfeng13 My-blog-layui | 14/4/2025 | 17/6/2026 | A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/v1/link/edit. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.1) | 0.40% | — | Zhenfeng13 My-blog-layui | 14/4/2025 | 17/6/2026 | A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/v1/blog/edit. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.47% | — | Lenve Vblog | 8/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function configure of the file blogserver/src/main/java/org/sang/config/WebSecurityConfig.java. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has… | |
| Aplazada | Media (6.5) | 0.40% | — | News Element Elementor Blog MagazineAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon News Element Elementor Blog Magazine news-element allows DOM-Based XSS.This issue affects News Element Elementor Blog Magazine: from n/a through <= 1.0.9. | |
| Aplazada | Media (6.5) | 0.40% | — | Suresh Prasad Showeblogin Showeblogin SocialAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh Prasad Showeblogin Social showeblogin-facebook-page-like-box allows DOM-Based XSS.This issue affects Showeblogin Social: from n/a through <= 7.0. | |
| Aplazada | Media (6.5) | 0.38% | — | Jeffikus Woo-tumblogAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in jeffikus WooTumblog woo-tumblog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooTumblog: from n/a through <= 2.1.4. | |
| Aplazada | Alta (8.1) | 0.84% | — | Informweb News AND Blog Designer PackAIPHPAI | 1/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InfornWeb News & Blog Designer Pack blog-designer-pack allows PHP Local File Inclusion.This issue affects News & Blog Designer Pack: from n/a through <= 4.0. | |
| Aplazada | Media (6.5) | 0.36% | — | Photoshelter FOR Photographers Blog Feed PluginAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PhotoShelter PhotoShelter for Photographers Blog Feed Plugin photoshelter-official-plugin allows Stored XSS.This issue affects PhotoShelter for Photographers Blog Feed Plugin: from n/a through <= 1.5.7. | |
| Aplazada | Media (6.5) | 0.36% | — | Athemeart News Magazine AND Blog ElementsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemeArt News, Magazine and Blog Elements news-magazine-and-blog-elements allows Stored XSS.This issue affects News, Magazine and Blog Elements: from n/a through <= 1.3. | |
| Analizada | Media (5.1) | 0.34% | — | Forestblog Project Forestblog | 31/3/2025 | 17/6/2026 | A vulnerability was found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this issue is some unknown functionality of the component Friend Link Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.1) | 0.34% | — | Forestblog Project Forestblog | 31/3/2025 | 17/6/2026 | A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /search. The manipulation of the argument keywords leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed… |