Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.43% | — | Wordpress Blogger Importer | 4/6/2023 | 16/6/2026 | A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affected is the function start/restart of the file blogger-importer.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. Upgrading to version 0.6 is… | |
| Modificada | Alta (8.8) | 0.26% | — | Import External Images Project Import External Images | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marty Thornley Import External Images plugin <= 1.4 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Secondlinethemes Auto Youtube Importer | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SecondLineThemes Auto YouTube Importer plugin <= 1.0.3 versions. | |
| Modificada | Alta (7.2) | 16% | — | Fastlinemedia Customizer Export/import | 8/5/2023 | 17/6/2026 | The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present | |
| Modificada | Media (6.1) | 0.56% | — | External Media Without Import Project External Media Without Import | 5/5/2023 | 17/6/2026 | A vulnerability was found in External Media without Import Plugin up to 1.0.0 on WordPress. It has been declared as problematic. This vulnerability affects the function print_media_new_panel of the file external-media-without-import.php. The manipulation of the argument url/error/width/height/mime-type leads to cross… | |
| Modificada | Media (4.8) | 0.37% | — | Json-content-importer Json Content Importer | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 versions. | |
| Modificada | Alta (8.8) | 1.5% | — | Envato ElementsEnvato Template KIT - Import | 7/3/2023 | 17/6/2026 | The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads due to insufficient validation of file type upon extracting uploaded Zip files in the installFreeTemplateKit and uploadTemplateKitZipFile functions. This makes it possible for attackers with… | |
| Modificada | Media (5.4) | 0.47% | — | Rssimport Project Rssimport | 16/1/2023 | 17/6/2026 | The RSSImport WordPress plugin through 4.6.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Media (4.9) | 0.88% | — | Simple-membership-plugin Simple Membership WP User Import | 12/1/2023 | 17/6/2026 | The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter. This makes it possible for authenticated attackers with administrative privileges to append additional… | |
| Modificada | Media (6.1) | 0.65% | — | Youngtechleads Members Import | 3/1/2023 | 17/6/2026 | The Members Import plugin for WordPress is vulnerable to Self Cross-Site Scripting via the user_login parameter in an imported CSV file in versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Crítica (9.8) | 2.4% | — | Cycle-import-check Project Cycle-import-check | 14/12/2022 | 17/6/2026 | The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization. | |
| Modificada | Media (6.1) | 0.43% | — | Xylusthemes WP Smart Import | 6/12/2022 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xylus Themes WP Smart Import plugin <= 1.0.2 on WordPress. | |
| Modificada | Media (6.5) | 0.37% | — | Addonspress Advanced Import | 5/12/2022 | 17/6/2026 | The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arbitrary plugins from WordPress.org, and activate arbitrary ones from the blog via CSRF attacks | |
| Modificada | Alta (7.2) | 1.1% | — | Postmagthemes Demo Import | 5/12/2022 | 17/6/2026 | The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE. | |
| Modificada | Media (4.9) | 0.75% | — | Villatheme S2W - Import Shopify TO Woocommerce | 18/11/2022 | 17/6/2026 | Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin <= 1.1.12 on WordPress. | |
| Modificada | Alta (8) | 1.1% | — | Codection Import AND Export Users AND Customers | 7/11/2022 | 17/6/2026 | The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files. | |
| Modificada | Alta (7.2) | 1.2% | — | Soflyy WP ALL Import | 7/11/2022 | 17/6/2026 | The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files | |
| Modificada | Alta (7.2) | 3.5% | — | Soflyy WP ALL Import | 7/11/2022 | 17/6/2026 | The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector. | |
| Analizada | Alta (7.2) | 1.3% | — | Fastlinemedia Customizer Export/import | 31/10/2022 | 17/6/2026 | The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | |
| Modificada | Media (4.3) | 0.59% | — | Jenkins JOB Import | 19/10/2022 | 17/6/2026 | Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (4.2) | 0.42% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 17/10/2022 | 17/6/2026 | The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce | |
| Modificada | Alta (7.2) | 1.1% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 17/10/2022 | 17/6/2026 | The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin | |
| Modificada | Alta (7.2) | 1.5% | — | Soflyy WP ALL Import | 21/9/2022 | 17/6/2026 | Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress. | |
| Modificada | Media (6.1) | 0.62% | — | WP Taxonomy Import Project WP Taxonomy Import | 16/9/2022 | 17/6/2026 | The WP Taxonomy Import WordPress plugin through 1.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 1.1% | — | Node-import Project Node-import | 25/7/2022 | 17/6/2026 | This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js". |