Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1775 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.14% | — | Mattermost Mobile | 13/11/2025 | 17/6/2026 | Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses | |
| Analizada | Media (4.3) | 0.18% | — | Mattermost Server | 13/11/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint | |
| Aplazada | Alta (8.8) | 0.46% | — | Scott Reilly Preserve Code FormattingAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve-code-formatting allows Object Injection.This issue affects Preserve Code Formatting: from n/a through <= 4.0.1. | |
| Analizada | Crítica (9.8) | 1.8% | 💥 PoC | Jorenbroekema Javascript Expression EvaluatorSilentmatt Javascript Expression Evaluator | 5/11/2025 | 17/6/2026 | The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and… | |
| Aplazada | Media (5.9) | 0.18% | — | Automattic WoocommerceAI | 29/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n/a through <= 10.0.2. | |
| Analizada | Baja (2) | 0.39% | — | Matthewdeaves Willow CMS | 27/10/2025 | 17/6/2026 | A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. | |
| Analizada | Baja (1.9) | 0.27% | — | Matthewdeaves Willow CMS | 27/10/2025 | 17/6/2026 | A security flaw has been discovered in Willow CMS up to 1.4.0. This issue affects some unknown processing of the file /admin/articles/add of the component Add Post Page. The manipulation of the argument title/body results in cross site scripting. The attack may be launched remotely. The exploit has been released to… | |
| Aplazada | Media (6.5) | 0.17% | — | Crestaproject Attesa ExtraAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrestaProject Attesa Extra attesa-extra allows Stored XSS.This issue affects Attesa Extra: from n/a through <= 1.4.7. | |
| Aplazada | Media (6.5) | 0.17% | — | Sayandatta WP Last Modified InfoAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayan Datta WP Last Modified Info wp-last-modified-info allows Stored XSS.This issue affects WP Last Modified Info: from n/a through <= 1.9.2. | |
| Aplazada | Media (6.5) | 0.20% | — | Matt Mcinvale Next Page NOT Next PostAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt McInvale Next Page, Not Next Post next-page-not-next-post allows Stored XSS.This issue affects Next Page, Not Next Post: from n/a through <= 0.3.0. | |
| Aplazada | Media (6.5) | 0.20% | — | Pagup Bulk Auto Image Title AttributeAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagup Bulk Auto Image Title Attribute bulk-image-title-attribute allows DOM-Based XSS.This issue affects Bulk Auto Image Title Attribute: from n/a through <= 2.0.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Aviplugins Custom Post Type AttachmentAI | 27/10/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Custom Post Type Attachment custom-post-type-pdf-attachment allows Stored XSS.This issue affects Custom Post Type Attachment: from n/a through <= 3.4.6. | |
| Aplazada | Media (5.9) | 0.22% | — | Tattersoftware WP TesseractAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tattersoftware WP Tesseract wp-tesseract allows Stored XSS.This issue affects WP Tesseract: from n/a through <= 1.0.2. | |
| Aplazada | Alta (7.4) | 0.27% | — | Sayandatta WP Last Modified InfoAI | 22/10/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Sayan Datta WP Last Modified Info wp-last-modified-info allows Remote Code Inclusion.This issue affects WP Last Modified Info: from n/a through <= 1.9.4. | |
| Aplazada | Alta (7.1) | 0.25% | — | Weboccult Technologies PVT LTD Email Attachment BY Order Status ProductsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technologies Pvt Ltd Email Attachment by Order Status & Products email-attachment-by-order-status-products allows Reflected XSS.This issue affects Email Attachment by Order Status & Products: from n/a… | |
| Aplazada | Crítica (9.8) | 0.59% | — | Boldthemes GoldenblattAI | 22/10/2025 | 5/10/2026 | Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows Object Injection.This issue affects Goldenblatt: from n/a through < 1.3.0. | |
| Analizada | Media (6.1) | 0.32% | — | Mattermost Desktop | 16/10/2025 | 17/6/2026 | Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the… | |
| Analizada | Alta (8.1) | 0.34% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState | |
| Analizada | Alta (8.1) | 0.42% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the OAuth state. | |
| Analizada | Baja (3.7) | 0.27% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth client secrets | |
| Analizada | Media (5.4) | 0.30% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create verified user accounts with arbitrary email domains via malicious Slack import data to bypass email-based team access restrictions | |
| Analizada | Media (4.3) | 0.33% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint | |
| Modificada | Media (4.3) | 0.31% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover active public channels and their metadata via the `/api/v4/teams/{team_id}/channels/ids` endpoint | |
| Aplazada | Media (5.3) | 0.29% | — | ZIP AttachmentsAI | 15/10/2025 | 17/6/2026 | The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post status validation in the za_create_zip_callback function in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to download… | |
| Aplazada | Media (5.3) | 0.24% | — | ZIP AttachmentsAI | 15/10/2025 | 17/6/2026 | The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to delete arbitrary files from the current wp_upload_dir… |