Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.36% | 💥 PoC | Iqonic Design GraphinaAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows PHP Local File Inclusion.This issue affects Graphina: from n/a through <= 3.0.4. | |
| Aplazada | Media (5.4) | 0.33% | — | Iqonic Design GraphinaAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Graphina: from n/a through <= 3.0.4. | |
| Aplazada | Alta (7.1) | 0.15% | — | John Weissberg Print Science DesignerAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in John Weissberg Print Science Designer print-science-designer allows Stored XSS.This issue affects Print Science Designer: from n/a through <= 1.3.155. | |
| Analizada | Alta (7.1) | 0.54% | 💥 Exploit | Etoilewebdesign Front END Users | 22/4/2025 | 17/6/2026 | The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Crítica (9.1) | 0.61% | — | Stellarwp Kadence Woocommerce Email DesignerAI | 16/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allows Upload a Web Shell to a Web Server.This issue affects Kadence WooCommerce Email Designer: from n/a through <= 1.5.14. | |
| Aplazada | Media (6.5) | 0.32% | — | Fetchdesigns Sign-up SheetsAI | 15/4/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Code Injection.This issue affects Sign-up Sheets: from n/a through <= 2.3.0.1. | |
| Aplazada | Alta (7.5) | 0.73% | — | John Weissberg Print Science DesignerAI | 11/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John Weissberg Print Science Designer print-science-designer allows Path Traversal.This issue affects Print Science Designer: from n/a through <= 1.3.155. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Vertim Neon Product Designer FOR WoocommerceAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-designer-for-woocommerce allows SQL Injection.This issue affects Neon Product Designer: from n/a through <= 2.2.0. | |
| Aplazada | Alta (7.6) | 0.50% | — | Solwininfotech WP Social Stream DesignerAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in solwininfotech WP Social Stream Designer social-stream-design allows Blind SQL Injection.This issue affects WP Social Stream Designer: from n/a through <= 1.3. | |
| Aplazada | Alta (7.1) | 0.19% | — | Ydesignservices Multiple Location Google MAPAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ydesignservices Multiple Location Google Map multiple-location-google-map allows Stored XSS.This issue affects Multiple Location Google Map: from n/a through <= 1.1. | |
| Aplazada | Media (5.4) | 0.22% | — | Designinvento DirectorypressAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Designinvento DirectoryPress directorypress allows Cross Site Request Forgery.This issue affects DirectoryPress: from n/a through <= 3.6.22. | |
| Modificada | Crítica (9.8) | 22% | 💥 PoC | Etoilewebdesign Front END Users | 2/4/2025 | 17/6/2026 | The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Modificada | Media (4.9) | 0.45% | — | Etoilewebdesign Front END Users | 2/4/2025 | 17/6/2026 | The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versions up to, and including, 3.2.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.1) | 0.84% | — | Informweb News AND Blog Designer PackAIPHPAI | 1/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InfornWeb News & Blog Designer Pack blog-designer-pack allows PHP Local File Inclusion.This issue affects News & Blog Designer Pack: from n/a through <= 4.0. | |
| Aplazada | Media (6.5) | 0.36% | — | Devscred Design BlocksAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred Design Blocks exclusive-blocks allows Stored XSS.This issue affects Design Blocks: from n/a through <= 1.2.5. | |
| Aplazada | Media (6.4) | 0.25% | — | WdesignkitAI | 1/4/2025 | 17/6/2026 | The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom widgets in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (4.8) | 0.21% | — | Softpulseinfotech SP Blog DesignerAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Blog Designer: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Designnbuy DesignoAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in designnbuy DesignO designo allows Cross Site Request Forgery.This issue affects DesignO: from n/a through <= 2.6.0. | |
| Aplazada | Media (4.3) | 0.28% | — | Creativewerkdesigns Export Order Product Customer Coupon FOR Woocommerce TO Google SheetsAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Creative Werk Designs Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets wpsyncsheets-woocommerce.This issue affects Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets: from n/a through <= 1.8.2. | |
| Aplazada | Alta (7.5) | 1.0% | — | Designingmedia HostikoAI | 26/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko hostiko allows PHP Local File Inclusion.This issue affects Hostiko: from n/a through < 30.1. | |
| Aplazada | Alta (7.1) | 0.39% | — | Designingmedia HostikoAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designingmedia Hostiko hostiko allows Reflected XSS.This issue affects Hostiko: from n/a through < 30.1. | |
| Analizada | Media (6.1) | 0.17% | — | Design Comuni Italia | 25/3/2025 | 17/6/2026 | The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks. | |
| Aplazada | Media (6.4) | 0.23% | — | Designthemes Core FeaturesAI | 25/3/2025 | 17/6/2026 | The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Aplazada | Alta (7.1) | 0.18% | — | Damian Orzol Contact Form 7 Material DesignAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design cf7-material-design allows Stored XSS.This issue affects Contact Form 7 Material Design: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.3) | 0.47% | — | Designmodo Logo SliderAI | 18/3/2025 | 17/6/2026 | The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.7.3. This is due to the software allowing users to execute an action that does not properly validate a value before… |