Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

430 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.45%—Strangerstudios Memberlite Shortcodes31/10/202317/6/2026
The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such…
ModificadaMedia (5.4)0.64%—Simple Shortcodes Project Simple Shortcodes30/10/202317/6/2026
The Simple Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above…
ModificadaMedia (5.4)0.41%—Shortcode Menu Project Shortcod Menu30/10/202317/6/2026
The Shortcode Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortmenu' shortcode in versions up to, and including, 3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and…
ModificadaMedia (6.1)0.33%—ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters26/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions.
ModificadaMedia (4.8)0.41%—Anuragdeshmukh CPT Shortcode Generator25/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anurag Deshmukh CPT Shortcode Generator plugin <= 1.0 versions.
ModificadaAlta (7.5)0.58%—Halulu Simple-download-button-shortcode17/10/202316/6/2026
A vulnerability classified as problematic has been found in Halulu simple-download-button-shortcode Plugin 1.0 on WordPress. Affected is an unknown function of the file simple-download-button_dl.php of the component Download Handler. The manipulation of the argument file leads to information disclosure. It is possible…
ModificadaMedia (5.4)0.47%—Sazzadh Testimonial Slider Shortcode16/10/202317/6/2026
The Testimonial Slider Shortcode WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users…
ModificadaMedia (5.4)0.40%—Hoosoft Magee Shortcodes16/10/202317/6/2026
The Magee Shortcodes WordPress plugin through 2.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (6.1)0.42%—Mpembed WP Matterport Shortcode16/10/202317/6/2026
The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting it in attributes, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin
ModificadaMedia (5.4)0.47%—Mpembed WP Matterport Shortcode16/10/202317/6/2026
The WP Matterport Shortcode WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (8.8)0.21%—Anuragdeshmukh CPT Shortcode Generator16/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Anurag Deshmukh CPT Shortcode Generator plugin <= 1.0 versions.
ModificadaAlta (8.8)0.21%—Bainternet Shortcodes UI10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 versions.
AnalizadaAlta (8.8)0.26%—ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions.
ModificadaAlta (8.8)0.25%—Web-argument Google-map-shortcode3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez plugin <= 3.1.2 versions.
ModificadaMedia (5.4)0.36%—Rescuethemes Rescue Shortcodes2/10/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored XSS.This issue affects Rescue Shortcodes: from n/a through 2.5.
ModificadaMedia (5.4)0.36%—Wpruse ART Decoration Shortcode1/9/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Artem Abramovich Art Decoration Shortcode plugin <= 1.5.6 versions.
ModificadaMedia (5.4)0.43%—Mpembed WP Matterport Shortcode30/8/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Julien Berthelot / MPEmbed WP Matterport Shortcode plugin <= 2.1.4 versions.
ModificadaAlta (8.8)0.26%—Pluginpress Shortcode Imdb18/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kemal YAZICI - PluginPress Shortcode IMDB plugin <= 6.0.8 versions.
ModificadaAlta (8.8)1.7%—Nicdark ND Shortcodes4/7/202317/6/2026
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
ModificadaMedia (5.4)0.44%—Nicdark ND Shortcodes4/7/202317/6/2026
The ND Shortcodes WordPress plugin before 7.0 does not validate and escape numerous of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaCrítica (9.8)40%—Advancedfilemanager File Manager Advanced Shortcode27/6/202317/6/2026
The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.
ModificadaMedia (5.4)0.36%—Iframe Shortcode Project Iframe Shortcode26/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flyn San IFrame Shortcode plugin <= 1.0.5 versions.
ModificadaMedia (5.4)0.36%—Simple Vimeo Shortcode Project Simple Vimeo Shortcode21/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Grant Kimball Simple Vimeo Shortcode plugin <= 2.9.1 versions.
ModificadaMedia (6.1)0.38%—Google MAP Shortcode Project Google MAP Shortcode19/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Alain Gonzalez Google Map Shortcode plugin <= 3.1.2 versions.
ModificadaMedia (5.4)0.44%—Web-argument Google MAP Shortcode19/6/202317/6/2026
The Google Map Shortcode WordPress plugin through 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such…