Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
2142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.52% | — | Carmelo Simple Student Alumni System | 2/3/2026 | 17/6/2026 | code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php. | |
| Analizada | Media (4.9) | 0.43% | — | Carmelo Simple Student Alumni System | 2/3/2026 | 17/6/2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php. | |
| Analizada | Media (4.9) | 0.43% | — | Carmelo Simple Student Alumni System | 2/3/2026 | 17/6/2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?teacherID=. | |
| Aplazada | Media (6.4) | 0.20% | — | Simple Download MonitorAI | 27/2/2026 | 17/6/2026 | The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Alta (8.6) | 0.29% | — | Simple ERPAI | 26/2/2026 | 17/6/2026 | SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input validation allows an authenticated attacker to prepare a malicious query to the database that will be executed. This issue was fixed in 6.30@A04.4_u06. | |
| Analizada | Media (5.5) | 0.61% | — | Haben-cs9 Simple AND Nice Shopping Cart Script | 25/2/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Modificada | Media (4.8) | 0.39% | — | Getsimple-ce Getsimple CMS | 24/2/2026 | 14/7/2026 | GetSimpleCMS Community Edition (CE) versions prior to 3.3.22 (3.3.16 tested) contains a stored cross-site scripting (XSS) vulnerability in the Theme to Components functionality within components.php. User-supplied input provided to the "slug" field of a component is stored without proper output encoding. While other… | |
| Aplazada | Media (5.3) | 0.34% | — | Plugin-planet Simple Ajax ChatAI | 23/2/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Jeff Starr Simple Ajax Chat simple-ajax-chat allows Retrieve Embedded Sensitive Data.This issue affects Simple Ajax Chat: from n/a through <= 20251121. | |
| Analizada | Alta (8.8) | 0.54% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication. | |
| Analizada | Alta (8.7) | 0.47% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apache AllowOverride is disabled (common in hardened or shared hosting environments), these protections are silently ignored, allowing… | |
| Analizada | Media (6.9) | 0.25% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or restricted, allowing an attacker to embed malicious JavaScript. When… | |
| Analizada | Alta (7.1) | 0.17% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker can craft a malicious web page that silently triggers a file upload request from an authenticated victim’s browser. The request is accepted… | |
| Analizada | Media (5.5) | 0.59% | — | Oretnom23 Simple Responsive Tourism Website | 20/2/2026 | 17/6/2026 | A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component Registration. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Media (6.5) | 0.39% | — | Simplefilelist Simple File ListAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Path Traversal.This issue affects Simple File List: from n/a through <= 6.1.15. | |
| Aplazada | Alta (7.5) | 0.35% | — | Whatwouldjessedo Simple Retail MenusAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in whatwouldjessedo Simple Retail Menus simple-retail-menus allows PHP Local File Inclusion.This issue affects Simple Retail Menus: from n/a through <= 4.2.1. | |
| Aplazada | Alta (7.1) | 0.18% | — | Peterwsterling Simple Archive GeneratorAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in peterwsterling Simple Archive Generator simple-archive-generator allows Reflected XSS.This issue affects Simple Archive Generator: from n/a through <= 5.2. | |
| Aplazada | Alta (7.1) | 0.27% | — | Jezza101 Bbpress Simple Advert UnitsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jezza101 bbpress Simple Advert Units bbpress-simple-advert-units allows Reflected XSS.This issue affects bbpress Simple Advert Units: from n/a through <= 0.41. | |
| Aplazada | Media (6.5) | 0.24% | — | Simple-membership-plugin Simple MembershipAI | 19/2/2026 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, and including, 4.7.0 via the Stripe webhook handler. This is due to the plugin only validating webhook signatures when the stripe-webhook-signing-secret setting is configured, which is empty by… | |
| Aplazada | Media (4.3) | 0.19% | — | Simple-membership-plugin Simple MembershipAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in wp.insider Simple Membership simple-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Membership: from n/a through <= 4.6.9. | |
| Aplazada | Media (6.4) | 0.26% | — | Really-simple-plugins ComplianzAI | 18/2/2026 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cmplz-accept-link shortcode in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.23% | — | Simple PlyrAI | 14/2/2026 | 17/6/2026 | The Simple Plyr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'poster' parameter in the 'plyr' shortcode in all versions up to, and including, 0.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.2) | 0.36% | — | Super Simple Contact FormAI | 14/2/2026 | 17/6/2026 | The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' parameter in all versions up to, and including, 1.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.4) | 0.19% | — | Simple WP Colorfull AccordionAI | 14/2/2026 | 17/6/2026 | The Simple Wp colorfull Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in the 'accordion' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Baja (2.1) | 0.31% | — | Oretnom23 Simple Responsive Tourism Website | 8/2/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Master.php?f=save_package. The manipulation of the argument Title leads to cross site scripting. The attack can be initiated remotely. The… | |
| Analizada | Baja (2.1) | 0.41% | — | Oretnom23 Simple Responsive Tourism Website | 8/2/2026 | 17/6/2026 | A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the file /tourism/classes/Master.php?f=register of the component Registration. Executing a manipulation of the argument firstname/lastname/username can lead to cross site scripting. It is possible to… |