Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

379 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)15%💥 ExploitMooveagency Import XML AND RSS Feeds7/7/202117/6/2026
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.
ModificadaCrítica (9.1)1.6%—Xylusthemes WP Smart Import7/7/202117/6/2026
Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via the file field.
ModificadaMedia (4.3)0.76%—Mendix Excel Importer12/5/202117/6/2026
A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an exception that could expose information about the Application-Server and the used XML-Framework.
ModificadaAlta (7.2)1.8%—College Publisher Import Project College Publisher Import6/5/202117/6/2026
The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.
ModificadaAlta (8.8)0.65%—Themegrill Demo Importer5/5/202117/6/2026
themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.
ModificadaCrítica (9.1)4.1%💥 ExploitThemegrill Demo Importer5/5/202117/6/2026
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
ModificadaAlta (8)1.8%—Codection Import AND Export Users AND Customers4/11/202017/6/2026
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
ModificadaAlta (8.8)1.7%—Webtoffee Import Export Wordpress Users23/4/202017/6/2026
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
ModificadaAlta (8.8)1.6%—Cyberchimps Gutenberg & Elementor Templates Importer FOR Responsive23/4/202017/6/2026
The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests.
ModificadaCrítica (9.8)1.4%—Fordnn Usersexportimport21/1/202017/6/2026
The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data.
ModificadaMedia (6.1)4.0%💥 ExploitImport Legacy Media Project Import Legacy Media27/12/201917/6/2026
Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
ModificadaAlta (8.2)0.59%—Jenkins Spira Importer17/12/201917/6/2026
Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
ModificadaMedia (5.5)0.32%—Jenkins Spira Importer21/11/201917/6/2026
Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaAlta (7.3)5.1%💥 ExploitWebtoffee Import Export Wordpress Users23/8/201917/6/2026
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.
ModificadaAlta (8.8)0.69%—Codection Import Users From CSV With Meta22/8/201917/6/2026
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
ModificadaMedia (6.1)0.93%—Codection Import Users From CSV With Meta22/8/201917/6/2026
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
ModificadaMedia (6.1)0.91%—Codection Import Users From CSV With Meta22/8/201917/6/2026
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
ModificadaAlta (7.5)2.3%—Codection Import Users From CSV With Meta22/8/201917/6/2026
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
ModificadaMedia (6.1)0.91%—Soflyy WP ALL Import20/8/201917/6/2026
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
ModificadaMedia (6.1)0.91%—Soflyy WP ALL Import20/8/201917/6/2026
The wp-all-import plugin before 3.4.6 for WordPress has XSS.
ModificadaAlta (7.5)1.4%💥 PoCSoflyy WP ALL Import20/8/201917/6/2026
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
ModificadaCrítica (9.8)1.8%—Soflyy WP ALL Import20/8/201917/6/2026
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
ModificadaMedia (6.1)0.91%—Soflyy WP ALL Import20/8/201917/6/2026
The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
ModificadaAlta (8.8)0.65%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV14/8/201917/6/2026
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
ModificadaMedia (6.1)0.96%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV12/8/201917/6/2026
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.