Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.70% | — | Vibethemes Wordpress Learning Management System | 31/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3. | |
| Modificada | Alta (8.8) | 0.56% | — | Vibethemes Wordpress Learning Management System | 18/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.2. | |
| Modificada | Alta (8.8) | 0.48% | — | Vibethemes Wordpress Learning Management System | 18/12/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2. | |
| Modificada | Alta (8.8) | 0.58% | — | Vibethemes Wordpress Learning Management System | 18/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.2. | |
| Modificada | Alta (8.8) | 0.44% | — | Vibethemes Wordpress Learning Management System | 18/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3. | |
| Modificada | Alta (8.8) | 0.69% | — | Vibethemes Wordpress Learning Management System | 18/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.2. | |
| Modificada | Alta (8.8) | 0.46% | — | Vibethemes Wordpress Learning Management System | 18/12/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Code Injection.This issue affects WPLMS: from n/a through < 1.9.9.5. | |
| Modificada | Alta (8.8) | 0.69% | — | Vibethemes Wordpress Learning Management System | 18/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.3. | |
| Modificada | Alta (8.5) | 0.47% | — | Vibethemes Wordpress Learning Management System | 18/12/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2. | |
| Modificada | Alta (8.8) | 0.60% | — | Vibethemes Wordpress Learning Management System | 18/12/2024 | 17/6/2026 | Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9. | |
| Modificada | Alta (8.8) | 0.62% | — | Vibethemes Wordpress Learning Management System | 18/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3. | |
| Aplazada | Media (6.4) | 0.35% | — | Crmperks Wordpress Helpdesk IntegrationAI | 16/12/2024 | 17/6/2026 | The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'crm-perks-tickets' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Alta (7.1) | 0.44% | — | Koolkatwebdesigns Jcarousel FOR WordpressAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in koolkatwebdesigns jCarousel jcarousel-for-wordpress allows Stored XSS.This issue affects jCarousel: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Mattwalters Wordpress FilterAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mattwalters WordPress Filter wordpress-filter allows Stored XSS.This issue affects WordPress Filter: from n/a through <= 1.4.1. | |
| Aplazada | Media (4.3) | 0.43% | — | ANH Tran Falcon Wordpress Optimizations TweaksAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Anh Tran Falcon – WordPress Optimizations & Tweaks falcon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Falcon – WordPress Optimizations & Tweaks: from n/a through <= 2.8.3. | |
| Modificada | Alta (8.8) | 0.56% | — | Cimatti Wordpress Contact Forms | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Forms by Cimatti: from n/a through 1.5.7. | |
| Aplazada | Media (4.3) | 0.51% | — | Webtoffee Wordpress Backup & MigrationAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WebToffee WordPress Backup & Migration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Backup & Migration: from n/a through 1.4.0. | |
| Aplazada | Media (6.4) | 0.36% | — | IPS Grid System Wordpress Book PluginAI | 12/12/2024 | 17/6/2026 | The WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_book_showcase' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user… | |
| Aplazada | Media (6.4) | 0.36% | — | Wordpress Portfolio PluginAI | 12/12/2024 | 17/6/2026 | The WordPress Portfolio Plugin – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_portfolio' shortcode in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on… | |
| Aplazada | Baja (3.7) | 0.38% | — | Jerod Santo Wordpress ConsoleAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Console: from n/a through 0.3.9. | |
| Aplazada | Media (5.3) | 0.76% | — | Miniorange Wordpress Social Login AND RegisterAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.0. | |
| Aplazada | Baja (3.5) | 0.44% | — | Miniorange Wordpress Social LoginAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.5.14. | |
| Aplazada | Media (4.3) | 0.53% | — | Zendesk Support FOR WordpressAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Zendesk Zendesk Support for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zendesk Support for WordPress: from n/a through 1.8.4. | |
| Aplazada | Media (6.1) | 0.37% | — | Worksmart Wordpress Payment SimplepayAI | 7/12/2024 | 17/6/2026 | The 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg() function without appropriate escaping on the URL in all versions up to, and including, 5.2.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (6.1) | 0.29% | — | Wordpress Drag Drop Builder Human Face Detector PRE Built Templates Spam Protection User Email Notifications MoreAI | 7/12/2024 | 17/6/2026 | The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.19 due to insufficient input sanitization and output escaping.… |