Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.6) | 0.17% | — | Webandprint AR FOR WordpressAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: from n/a through <= 8.34. | |
| Aplazada | Media (5.9) | 0.22% | — | WordpressAI | 23/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute… | |
| Aplazada | Media (4.3) | 0.27% | — | WordpressAI | 23/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it. This issue… | |
| Aplazada | Media (6.5) | 0.21% | — | Skyword API PluginAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skyword Skyword API Plugin skyword-plugin allows Stored XSS.This issue affects Skyword API Plugin: from n/a through <= 2.5.3. | |
| Aplazada | Media (5.9) | 0.22% | — | Modern Minds Magento 2 Wordpress IntegrationAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modern Minds Magento 2 WordPress Integration m2wp allows Stored XSS.This issue affects Magento 2 WordPress Integration: from n/a through <= 1.4.2.1. | |
| Modificada | Crítica (9.8) | 0.28% | — | Vibethemes Wordpress Learning Management System | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in VibeThemes WPLMS wplms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLMS : from n/a through <= 4.970. | |
| Aplazada | Media (6.5) | 0.31% | — | Slimndap Theater FOR WordpressAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Theater for WordPress theatre allows Stored XSS.This issue affects Theater for WordPress: from n/a through <= 0.18.8. | |
| Aplazada | Media (6.5) | 0.20% | — | Matthewordie BucketsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matthewordie Buckets buckets allows Stored XSS.This issue affects Buckets: from n/a through <= 0.3.9. | |
| Aplazada | Media (6.5) | 0.22% | — | Brajesh Singh Wordpress Widgets ShortcodeAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brajesh Singh WordPress Widgets Shortcode wp-widgets-shortcode allows Stored XSS.This issue affects WordPress Widgets Shortcode: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.3) | 0.32% | — | Strategy11 Another Wordpress Classifieds PluginAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Code Injection.This issue affects AWP Classifieds: from n/a through <= 4.4.3. | |
| Aplazada | Media (5.9) | 0.22% | — | Tmontg1 Form Generator FOR WordpressAIJotformAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tmontg1 Form Generator for WordPress form-generator-powered-by-jotform allows Stored XSS.This issue affects Form Generator for WordPress: from n/a through <= 1.52. | |
| Aplazada | Media (4.3) | 0.17% | — | Andy Moyle Emergency Password ResetAI | 22/9/2025 | 30/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Emergency Password Reset emergency-password-reset allows Cross Site Request Forgery.This issue affects Emergency Password Reset: from n/a through <= 9.3. | |
| Aplazada | Crítica (9.8) | 0.24% | — | Bedevious Password Reset With Code FOR Wordpress Rest APIAI | 18/9/2025 | 17/6/2026 | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers. | |
| Aplazada | Baja (3.2) | 0.15% | — | Clickstudios PasswordstateAI | 16/9/2025 | 30/9/2026 | Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section. | |
| Aplazada | Media (6.1) | 0.22% | — | WP Edit Password ProtectedAI | 11/9/2025 | 17/6/2026 | The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue | |
| Aplazada | Alta (7.2) | 0.56% | — | Import ANY XML CSV OR Excel File TO WordpressAI | 10/9/2025 | 17/6/2026 | The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functionality in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Analizada | Alta (7.1) | 0.63% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+2 | 9/9/2025 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Aplazada | Alta (8.8) | 0.33% | — | Webdevstudios Constant Contact FOR WordpressAI | 9/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: from n/a through 4.1.1. | |
| Aplazada | Alta (7.1) | 0.19% | — | Beaver Builder Wordpress AssistantAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from n/a through <= 1.5.2. | |
| Aplazada | Media (6.5) | 0.17% | — | George Sexton Wordpress Events Calendar Plugin ConnectdailyAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Sexton WordPress Events Calendar Plugin – connectDaily connect-daily-web-calendar allows Stored XSS.This issue affects WordPress Events Calendar Plugin – connectDaily: from n/a through <= 1.5.5. | |
| Aplazada | Alta (7.1) | 0.13% | — | Wordpress Error Monitoring BY BugsnagAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tom Longridge WordPress Error Monitoring by Bugsnag bugsnag allows Stored XSS.This issue affects WordPress Error Monitoring by Bugsnag: from n/a through <= 1.6.3. | |
| Aplazada | Alta (8.1) | 0.71% | — | Wordpress Helpdesk IntegrationAI | 5/9/2025 | 25/9/2026 | The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.8.10 via the portal_type parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP… | |
| Aplazada | Alta (7.3) | 0.34% | — | Opentext Self Service Password ResetAI | 29/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Authentication Bypass.This issue affects Self Service Password Reset from before 4.8 patch 3. | |
| Aplazada | Media (6.5) | 0.21% | — | Stanton119 Wordpress HtmlAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stanton119 WordPress HTML custom-html-bodyhead allows Stored XSS.This issue affects WordPress HTML: from n/a through <= 0.51. | |
| Aplazada | Media (4.3) | 0.20% | — | Liquidthemes Liquid Reset Wordpress BeforeAI | 28/8/2025 | 17/6/2026 | Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate all of a site's… |