Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2442 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.26% | — | Weplugins User FrontendAI | 9/6/2026 | 23/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it… | |
| Aplazada | Crítica (9.1) | 0.37% | — | Catalyst Plugin AuthenticationAI | 9/6/2026 | 21/7/2026 | Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim. | |
| Aplazada | Media (5.5) | 0.29% | — | Stripe PluginAIBeikeshopAI | 7/6/2026 | 23/7/2026 | A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in improper authorization. The attack can… | |
| Aplazada | Media (4.4) | 0.33% | — | Weplugins WP MapsAI | 6/6/2026 | 23/7/2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (4.3) | 0.49% | — | SEO Plugin BY SquirrlyAI | 6/6/2026 | 23/7/2026 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 12.4.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Crítica (10) | 2.0% | 💥 Exploit | Shapedplugin LLC Product Slider PRO FOR WoocommerceAI | 5/6/2026 | 23/7/2026 | Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4. | |
| Aplazada | Alta (7.5) | 0.43% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14. | |
| Aplazada | Alta (7.5) | 0.39% | — | Really-simple-plugins Really Simple SecurityAI | 2/6/2026 | 22/7/2026 | The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge. | |
| Analizada | Media (5.1) | 0.39% | — | TFA Basic Plugins Project TFA Basic Plugins | 28/5/2026 | 21/7/2026 | An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Pluginus Active Products Tables FOR WoocommerceAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.9. | |
| Aplazada | Media (6.5) | 0.22% | — | Oplugins Booking ManagerAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Manager booking-manager allows Stored XSS.This issue affects Booking Manager: from n/a through <= 2.1.18. | |
| Aplazada | Alta (7.1) | 0.25% | — | HT Plugins HT Contact Form 7AI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through <= 2.8.2. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Pluginus Active Products Tables FOR WoocommerceAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.8. | |
| Aplazada | Media (6.5) | 0.33% | — | Strategy11 Another Wordpress Classifieds PluginAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= 4.4.5. | |
| Aplazada | Media (4.3) | 0.18% | — | Metamagic SEO PluginAI | 27/5/2026 | 17/6/2026 | The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the metamagic_update_options function. This makes it possible for unauthenticated attackers to modify the plugin's SEO settings,… | |
| Aplazada | Media (5.3) | 0.40% | — | Mojolicious Plugin StatsdAIPerl NET Statsd TinyAI | 26/5/2026 | 24/7/2026 | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Version 0.06 changes the module from being a statsd client to using a… | |
| Aplazada | Media (4.3) | 0.15% | — | Bplugins Tiktok FeedAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tiktok Feed: from n/a through 1.0.24. | |
| Aplazada | Alta (7.5) | 0.39% | — | Plainviewplugins MycryptocheckoutAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161. | |
| Aplazada | Media (6.5) | 0.17% | — | Pickplugins Team ShowcaseAI | 25/5/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a through 1.22.28. | |
| Aplazada | Alta (8.8) | 0.35% | — | Moosocial Store PluginAI | 25/5/2026 | 23/7/2026 | mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product… | |
| Aplazada | Media (4.3) | 0.35% | — | Shapedplugin Location WeatherAI | 22/5/2026 | 24/7/2026 | The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `lwp_clean_weather_transients()` functions in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.1) | 0.18% | — | Perl Catalyst Plugin AuthenticationAI | 21/5/2026 | 23/7/2026 | Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. | |
| Analizada | Crítica (10) | 1.0% | ⚠ Explotación activa💥 PoC | Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin | 21/5/2026 | 7/10/2026 | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been… | |
| Aplazada | Alta (8.8) | 0.82% | — | Sigmaplugin Advanced Database CleanerAI | 20/5/2026 | 24/7/2026 | The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 'template' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server,… | |
| Aplazada | Media (6.1) | 0.34% | — | Template Toolkit Template Plugin HtmlAI | 19/5/2026 | 19/9/2026 | Template::Plugin::HTML versions before 3.103 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in would not be properly escaped. An attacker could insert some… |