Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.19% | — | Suiteplugins Video & Photo Gallery FOR Ultimate MemberAI | 27/3/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-ultimate-member allows Server Side Request Forgery.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through <= 1.1.2. | |
| Modificada | Media (4.8) | 0.31% | — | Wpeverest User Registration & Membership | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Stored XSS.This issue affects User Registration: from n/a through <= 4.0.3. | |
| Aplazada | Alta (7.5) | 0.79% | — | Suiteplugins Login Widget FOR Ultimate MemberAI | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SuitePlugins Login Widget for Ultimate Member login-widget-for-ultimate-member allows PHP Local File Inclusion.This issue affects Login Widget for Ultimate Member: from n/a through <= 1.1.2. | |
| Aplazada | Alta (8.8) | 0.63% | — | S2member PROAI | 18/3/2025 | 17/6/2026 | The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the… | |
| Analizada | Alta (7.5) | 1.7% | 💥 Exploit | Wpcom Member | 14/3/2025 | 17/6/2026 | The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in all versions up to, and including, 1.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.1) | 0.15% | — | Naren Members Page Only FOR Logged IN UsersAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Naren Members page only for logged in users members-page-only-for-logged-in-users allows Stored XSS.This issue affects Members page only for logged in users: from n/a through <= 1.4.2. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Wpcom MemberAI | 7/3/2025 | 17/6/2026 | The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone' parameter when logging in. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an… | |
| Aplazada | Alta (7.5) | 0.72% | — | Ultimatemember Ultimate MemberAI | 5/3/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 2.10.0 due to insufficient escaping on the user supplied parameter and lack… | |
| Aplazada | Alta (7.1) | 0.32% | — | Cristian Lavaque S2memberAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member s2member allows Reflected XSS.This issue affects s2Member: from n/a through <= 241216. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Academist MembershipAI | 1/3/2025 | 17/6/2026 | The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.64% | — | Alloggio MembershipAI | 1/3/2025 | 17/6/2026 | The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity through the alloggio_membership_init_rest_api_facebook_login and alloggio_membership_init_rest_api_google_login functions.… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Setsail MembershipAI | 1/3/2025 | 17/6/2026 | The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a users identity through the social login. This makes it possible for unauthenticated attackers to log in as any user, including administrators and take over access… | |
| Aplazada | Media (4.3) | 0.29% | — | Subscriptions Memberships FOR PaypalAI | 26/2/2025 | 17/6/2026 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged… | |
| Aplazada | Media (5.3) | 0.55% | — | SuremembersAI | 26/2/2025 | 17/6/2026 | The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including restricted content. | |
| Analizada | Media (6.5) | 0.36% | — | Ultimatemember Ultimate Member | 21/2/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the user supplied parameter and lack of… | |
| Analizada | Media (6.1) | 0.43% | — | Clavaque S2member | 18/2/2025 | 17/6/2026 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114. This makes it… | |
| Analizada | Crítica (9.8) | 0.95% | — | S2member | 15/2/2025 | 17/6/2026 | The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input from the 's2member_pro_remote_op' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is… | |
| Analizada | Media (4.6) | 0.22% | — | Samsung Members | 4/2/2025 | 17/6/2026 | Improper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across multiple user profiles. | |
| Aplazada | Alta (7.1) | 0.32% | — | Wp.insider Simple Membership Custom MessagesAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple Membership Custom Messages simple-membership-custom-messages allows Reflected XSS.This issue affects Simple Membership Custom Messages: from n/a through <= 2.4. | |
| Aplazada | Media (4.3) | 0.24% | — | Ember Znet StackAI | 28/1/2025 | 17/6/2026 | A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert | |
| Aplazada | Alta (7.1) | 0.39% | — | Explara MembershipAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Explara Explara Membership explara-membership allows Reflected XSS.This issue affects Explara Membership: from n/a through <= 0.0.7. | |
| Analizada | Media (5.3) | 0.36% | — | Ultimatemember Ultimate Member | 18/1/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for unauthenticated… | |
| Analizada | Alta (7.5) | 0.53% | — | Ultimatemember Ultimate Member | 18/1/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied parameter and lack of… | |
| Analizada | Crítica (9.8) | 0.56% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 14/1/2025 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the user-controlled value supplied via the… | |
| Aplazada | Media (4.3) | 0.24% | — | Silabs Ember Znet StackAI | 13/1/2025 | 17/6/2026 | A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert |