Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
430 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.45% | — | Strangerstudios Memberlite Shortcodes | 31/10/2023 | 17/6/2026 | The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Media (5.4) | 0.64% | — | Simple Shortcodes Project Simple Shortcodes | 30/10/2023 | 17/6/2026 | The Simple Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… | |
| Modificada | Media (5.4) | 0.41% | — | Shortcode Menu Project Shortcod Menu | 30/10/2023 | 17/6/2026 | The Shortcode Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortmenu' shortcode in versions up to, and including, 3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Modificada | Media (6.1) | 0.33% | — | ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters | 26/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions. | |
| Modificada | Media (4.8) | 0.41% | — | Anuragdeshmukh CPT Shortcode Generator | 25/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anurag Deshmukh CPT Shortcode Generator plugin <= 1.0 versions. | |
| Modificada | Alta (7.5) | 0.58% | — | Halulu Simple-download-button-shortcode | 17/10/2023 | 16/6/2026 | A vulnerability classified as problematic has been found in Halulu simple-download-button-shortcode Plugin 1.0 on WordPress. Affected is an unknown function of the file simple-download-button_dl.php of the component Download Handler. The manipulation of the argument file leads to information disclosure. It is possible… | |
| Modificada | Media (5.4) | 0.47% | — | Sazzadh Testimonial Slider Shortcode | 16/10/2023 | 17/6/2026 | The Testimonial Slider Shortcode WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Modificada | Media (5.4) | 0.40% | — | Hoosoft Magee Shortcodes | 16/10/2023 | 17/6/2026 | The Magee Shortcodes WordPress plugin through 2.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.1) | 0.42% | — | Mpembed WP Matterport Shortcode | 16/10/2023 | 17/6/2026 | The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting it in attributes, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.47% | — | Mpembed WP Matterport Shortcode | 16/10/2023 | 17/6/2026 | The WP Matterport Shortcode WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.21% | — | Anuragdeshmukh CPT Shortcode Generator | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Anurag Deshmukh CPT Shortcode Generator plugin <= 1.0 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Bainternet Shortcodes UI | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 versions. | |
| Analizada | Alta (8.8) | 0.26% | — | ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Web-argument Google-map-shortcode | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez plugin <= 3.1.2 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Rescuethemes Rescue Shortcodes | 2/10/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored XSS.This issue affects Rescue Shortcodes: from n/a through 2.5. | |
| Modificada | Media (5.4) | 0.36% | — | Wpruse ART Decoration Shortcode | 1/9/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Artem Abramovich Art Decoration Shortcode plugin <= 1.5.6 versions. | |
| Modificada | Media (5.4) | 0.43% | — | Mpembed WP Matterport Shortcode | 30/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Julien Berthelot / MPEmbed WP Matterport Shortcode plugin <= 2.1.4 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Pluginpress Shortcode Imdb | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kemal YAZICI - PluginPress Shortcode IMDB plugin <= 6.0.8 versions. | |
| Modificada | Alta (8.8) | 1.7% | — | Nicdark ND Shortcodes | 4/7/2023 | 17/6/2026 | The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks | |
| Modificada | Media (5.4) | 0.44% | — | Nicdark ND Shortcodes | 4/7/2023 | 17/6/2026 | The ND Shortcodes WordPress plugin before 7.0 does not validate and escape numerous of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Crítica (9.8) | 40% | — | Advancedfilemanager File Manager Advanced Shortcode | 27/6/2023 | 17/6/2026 | The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users. | |
| Modificada | Media (5.4) | 0.36% | — | Iframe Shortcode Project Iframe Shortcode | 26/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flyn San IFrame Shortcode plugin <= 1.0.5 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Simple Vimeo Shortcode Project Simple Vimeo Shortcode | 21/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Grant Kimball Simple Vimeo Shortcode plugin <= 2.9.1 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Google MAP Shortcode Project Google MAP Shortcode | 19/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Alain Gonzalez Google Map Shortcode plugin <= 3.1.2 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Web-argument Google MAP Shortcode | 19/6/2023 | 17/6/2026 | The Google Map Shortcode WordPress plugin through 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… |