Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

622 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)3.4%—Textpattern7/8/202317/6/2026
Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive information via the plugin Upload function.
ModificadaMedia (6.1)0.89%💥 ExploitJohnniejodelljr Twittee Text Tweet31/7/202317/6/2026
The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.
ModificadaMedia (4.3)0.61%—Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+628/7/202317/6/2026
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers…
ModificadaMedia (6.5)0.69%—Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+728/7/202317/6/2026
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,…
ModificadaMedia (5.4)0.53%—Lanacodes Lana Text TO Image24/6/202317/6/2026
The Lana Text to Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lana_text_to_image' and 'lana_text_to_img' shortcode in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
ModificadaMedia (4.8)0.37%—Advanced Text Widget Project Advanced Text Widget22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Chirkov Advanced Text Widget plugin <= 2.1.2 versions.
ModificadaAlta (7.1)0.30%—Opentext Archive Center Administration24/5/202317/6/2026
The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft…
ModificadaAlta (7.8)0.28%—Opentext Documentum Content Server18/5/202317/6/2026
OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The software comes prepackaged with a root owned SUID binary dm_secure_writer. The binary has security controls in place preventing creation of a file in a non-owned directory,…
ModificadaCrítica (9.8)0.65%—Opentext Bizmanager1/5/202317/6/2026
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.
ModificadaAlta (8.8)1.1%—Textpattern28/4/202317/6/2026
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.
ModificadaAlta (8.8)0.89%—Random Text Project Random Text24/4/202317/6/2026
The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers.
ModificadaCrítica (9.8)0.82%—Litextension Leurlrewrite17/4/202317/6/2026
SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component.
ModificadaAlta (7.2)2.0%💥 PoCTextpattern12/4/202317/6/2026
An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted PHP file.
ModificadaAlta (7.8)0.38%—Marktext24/2/202317/6/2026
A vulnerability has been found in MarkText up to 0.17.1 on Windows and classified as critical. Affected by this vulnerability is an unknown functionality of the component WSH JScript Handler. The manipulation leads to code injection. Local access is required to approach this attack. The exploit has been disclosed to…
ModificadaMedia (6.1)0.50%—Textangular21/2/202317/6/2026
textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. There are no known patches.
ModificadaMedia (5.4)0.54%—Webberzone Contextual Related Posts6/2/202317/6/2026
The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.62%—Responsivevoice Text TO Speech6/2/202317/6/2026
The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (6.5)0.33%—Imageseo Optimize Images ALT Text (alt Tag) & Names FOR SEO Using AI23/1/202317/6/2026
The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.
ModificadaAlta (8.8)1.9%—Opentext Extended ECM18/1/202317/6/2026
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the authentication of the QDS endpoints of the Content Server. These endpoints can be used to create objects and execute arbitrary code.
ModificadaAlta (8.8)1.9%—Opentext Extended ECM18/1/202317/6/2026
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows an attacker to increase/decrease an arbitrary memory address by 1 and trigger a call to a method of a vftable with a vftable pointer value chosen by the attacker.
ModificadaAlta (8.8)1.7%—Opentext Extended ECM18/1/202317/6/2026
A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and executes Oscript code in HTML files,…
ModificadaAlta (8.8)17%—Opentext Extended ECM18/1/202317/6/2026
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user to evaluate webreports.
ModificadaAlta (7.5)17%—Opentext Extended ECM18/1/202317/6/2026
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an…
ModificadaAlta (8.1)1.4%—Opentext Extended ECM18/1/202317/6/2026
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate2 allows a low-privilege user to delete arbitrary files on the server's local filesystem.
ModificadaAlta (8.8)1.6%—Opentext Extended ECM18/1/202317/6/2026
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, which require a valid AdminPwd cookie, without knowing the password.
Orbitaley — Vulnerabilidades