Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 15% | 💥 Exploit | Wpallimport WP ALL Import | 18/7/2022 | 17/6/2026 | The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the… | |
| Modificada | Media (6.1) | 0.39% | — | Import CSV Files Project Import CSV Files | 17/7/2022 | 17/6/2026 | The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting | |
| Modificada | Media (6.5) | 0.77% | — | Mendix Excel Importer | 12/7/2022 | 17/6/2026 | A vulnerability has been identified in Mendix Excel Importer Module (Mendix 8 compatible) (All versions < V9.2.2), Mendix Excel Importer Module (Mendix 9 compatible) (All versions < V10.1.2). The affected component is vulnerable to XML Entity Expansion Injection. An attacker may use this to compromise the availability… | |
| Modificada | Media (6.1) | 0.79% | — | Visser Woocommerce - Product Importer | 11/7/2022 | 17/6/2026 | The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (7.2) | 1.4% | — | Soflyy WP ALL Import | 4/7/2022 | 17/6/2026 | The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE | |
| Modificada | Alta (7.2) | 1.3% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 27/6/2022 | 17/6/2026 | The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks | |
| Modificada | Media (6.1) | 0.79% | — | Ultimate Woocommerce CSV Importer Project Ultimate Woocommerce CSV Importer | 27/6/2022 | 17/6/2026 | The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.5) | 3.0% | 💥 Exploit | External Media Without Import Project External Media Without Import | 16/5/2022 | 17/6/2026 | The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are external medias, which could allow any authenticated users, such as subscriber to perform blind SSRF attacks | |
| Modificada | Alta (7.2) | 1.5% | — | Importwp Import WP | 2/5/2022 | 17/6/2026 | The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE | |
| Modificada | Media (4.8) | 0.71% | — | Codection Import AND Export Users AND Customers | 2/5/2022 | 17/6/2026 | The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues | |
| Modificada | Alta (8.8) | 0.58% | — | Rarathemes Rara ONE Click Demo Import | 29/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory. | |
| Modificada | Alta (8.1) | 0.48% | — | Accesspressthemes Access Demo Importer | 18/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media). | |
| Modificada | Media (6.5) | 0.49% | — | Accesspressthemes Access Demo Importer | 18/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin. | |
| Modificada | Alta (7.2) | 1.5% | — | Secondlinethemes Podcast Importer Secondline | 11/4/2022 | 17/6/2026 | The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file | |
| Modificada | Alta (7.2) | 1.7% | — | Ocdi ONE Click Demo Import | 11/4/2022 | 17/6/2026 | The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed | |
| Modificada | Alta (7.2) | 1.4% | — | Catchplugins Catch Themes Demo Import | 7/3/2022 | 17/6/2026 | The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set… | |
| Modificada | Media (4.8) | 0.65% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 28/2/2022 | 17/6/2026 | The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues | |
| Modificada | Alta (7.5) | 4.3% | 💥 PoC | Vjinfotech WP Import ExportVjinfotech WP Import Export Lite | 18/1/2022 | 17/6/2026 | The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated… | |
| Modificada | Media (4.8) | 0.62% | — | Soflyy WP ALL Import | 6/12/2021 | 17/6/2026 | The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8.1) | 1.1% | — | Hashthemes Demo Importer | 1/11/2021 | 17/6/2026 | The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads. | |
| Modificada | Alta (7.2) | 56% | 💥 Exploit | Catchplugins Catch Themes Demo Import | 21/10/2021 | 17/6/2026 | The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to… | |
| Modificada | Media (4.8) | 0.99% | — | Indeed-job-importer Project Indeed-job-importer | 19/10/2021 | 17/6/2026 | The Indeed Job Importer WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/indeed-job-importer/trunk/indeed-job-importer.php file which allowed attackers with administrative user access to inject arbitrary web… | |
| Modificada | Media (5.7) | 0.42% | — | Catchplugins Catch Scroll Progress BARCatchplugins Catch Sticky MenuCatchplugins Catch Themes Demo ImportCatchplugins Catch Under Construction+6 | 18/10/2021 | 17/6/2026 | Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before… | |
| Modificada | Alta (8.8) | 1.7% | — | Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+39 | 11/10/2021 | 17/6/2026 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the… | |
| Modificada | Alta (7.5) | 1.7% | — | Podcast Importer Secondline | 7/7/2021 | 17/6/2026 | Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed parameter in a secondline_import_initialize action to the secondlinepodcastimport page. |