Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.50% | — | Codeastro Membership Management System | 27/9/2024 | 17/6/2026 | The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information. | |
| Analizada | Media (6.1) | 0.35% | — | Codeastro Membership Management System | 27/9/2024 | 17/6/2026 | Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component. | |
| Modificada | Alta (8.8) | 0.48% | — | Ultimatemember Forumwp | 6/9/2024 | 17/6/2026 | The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'user_id' user controlled key. This makes it possible for authenticated… | |
| Modificada | Crítica (9.8) | 0.56% | — | Wpcom Member | 6/9/2024 | 17/6/2026 | The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_user() during registration. This makes it possible for unauthenticated attackers to update their role to that of an… | |
| Analizada | Media (5.3) | 0.44% | — | Coffee2code Remember ME Controls | 6/9/2024 | 17/6/2026 | The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the… | |
| Analizada | Media (5.4) | 0.28% | — | Codeastro Membership Management System | 2/9/2024 | 17/6/2026 | CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS. | |
| Analizada | Media (6.1) | 0.34% | — | Memberpress | 30/8/2024 | 17/6/2026 | The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr_key' parameter in all versions up to, and including, 1.11.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Crítica (10) | 0.54% | — | Wpindeed Ultimate Membership PRO | 19/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Modificada | Crítica (9.8) | 0.55% | — | Wpindeed Ultimate Membership PRO | 19/8/2024 | 17/6/2026 | Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpindeed Ultimate Membership PROAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Aplazada | Media (6.4) | 1.1% | 💥 PoC | ArmemberAI | 17/8/2024 | 17/6/2026 | The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.0.37 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.49% | — | Opal MembershipAI | 12/8/2024 | 17/6/2026 | The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (4.3) | 0.59% | — | Opal MembershipAI | 12/8/2024 | 17/6/2026 | The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticated attackers, with subscriber-level access and above, to view… | |
| Analizada | Alta (8.8) | 0.33% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php. | |
| Analizada | Alta (7.6) | 1.1% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter. | |
| Analizada | Crítica (9.8) | 1.0% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters. | |
| Analizada | Crítica (9.8) | 1.2% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Media (6.1) | 0.19% | — | Tipsandtricks-hq WP Emember | 5/8/2024 | 17/6/2026 | The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Modificada | Media (6.5) | 0.52% | — | Strangerstudios Paid Memberships PRO | 30/7/2024 | 17/6/2026 | The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector. | |
| Analizada | Media (4.9) | 0.56% | — | Strangerstudios Paid Memberships PRO | 30/7/2024 | 17/6/2026 | The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site. | |
| Aplazada | Media (6.5) | 0.34% | — | Wpdarko Team MembersAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Members allows Stored XSS.This issue affects Team Members: from n/a through 5.3.3. | |
| Analizada | Media (6.8) | 0.43% | — | Tipsandtricks-hq WP Emember | 13/7/2024 | 17/6/2026 | The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |
| Analizada | Alta (7.1) | 0.39% | — | Tipsandtricks-hq WP Emember | 13/7/2024 | 17/6/2026 | The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Alta (8.8) | 0.66% | — | Tipsandtricks-hq WP Emember | 13/7/2024 | 17/6/2026 | The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server | |
| Analizada | Media (6.1) | 0.37% | — | Tipsandtricks-hq WP Emember | 13/7/2024 | 17/6/2026 | The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks |