Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
721 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Sayandatta Ultimate Social Comments Email Notification Lazy LoadAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayan Datta Ultimate Social Comments – Email Notification & Lazy Load allows Stored XSS.This issue affects Ultimate Social Comments – Email Notification & Lazy Load: from n/a through 1.4.8. | |
| Modificada | Media (4.3) | 0.20% | — | Easysocialfeed Easy Social Feed | 31/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Easy Social Feed.This issue affects Easy Social Feed: from n/a through 6.5.6. | |
| Modificada | Media (6.5) | 0.34% | — | Easysocialfeed Easy Social Feed | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Social Feed allows Stored XSS.This issue affects Easy Social Feed: from n/a through 6.5.3. | |
| Aplazada | Alta (7.1) | 0.35% | — | Idiom Easy Social Share ButtonsAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Appscreo Easy Social Share Buttons allows Reflected XSS.This issue affects Easy Social Share Buttons: from n/a through 9.4. | |
| Modificada | Media (5.4) | 0.40% | — | Easysocialfeed Easy Social Feed | 21/3/2024 | 17/6/2026 | The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'efb_likebox' shortcode in all versions up to, and including, 6.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Modificada | Media (4.3) | 0.24% | — | Easysocialfeed Easy Social Feed | 21/3/2024 | 17/6/2026 | The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.4. This is due to missing or incorrect nonce validation on the save_groups_list function. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (4.3) | 0.24% | — | Easysocialfeed Easy Social Feed | 21/3/2024 | 17/6/2026 | The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.4. This is due to missing or incorrect nonce validation on the esf_insta_save_access_token and efbl_save_facebook_access_token functions. This… | |
| Modificada | Alta (8.8) | 0.67% | — | Sygnoos Social Media Share Buttons | 20/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0. | |
| Analizada | Media (6.1) | 0.40% | — | Patelmilap Widget FOR Social Page Feeds | 18/3/2024 | 17/6/2026 | The Widget for Social Page Feeds WordPress plugin before 6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.38% | — | Shahaji9 Advanced Social Feeds Widget & Shortcode | 18/3/2024 | 17/6/2026 | The Advanced Social Feeds Widget & Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.77% | — | Mediabetaprojects Enjoy Social Feed | 18/3/2024 | 17/6/2026 | The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing any authenticated users, such as subscriber to perform such action | |
| Analizada | Alta (8.8) | 0.35% | — | Mediabetaprojects Enjoy Social Feed | 18/3/2024 | 17/6/2026 | The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to admin_init, allowing unauthenticated users to call them and unlink arbitrary users Instagram Account for example | |
| Modificada | Alta (8.8) | 0.77% | — | Sygnoos Social Media Share Buttons | 16/3/2024 | 17/6/2026 | The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserialization of untrusted input through the attachmentUrl parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP… | |
| Modificada | Media (5.4) | 0.34% | — | Catchsquare WP Social Widget | 15/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget allows Stored XSS.This issue affects WP Social Widget: from n/a through 2.2.5. | |
| Modificada | Media (5.3) | 0.44% | — | Wpmet WP Social Login AND Register Social Counter | 13/3/2024 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable… | |
| Modificada | Media (5.4) | 0.51% | — | Heateor Sassy Social Share | 6/3/2024 | 17/6/2026 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share' shortcode in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escaping on user supplied attributes such as 'url'. This makes… | |
| Modificada | Media (5.4) | 0.37% | — | Nextendweb Nextend Social Login | 2/3/2024 | 17/6/2026 | The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting via the ‘error_description’ parameter in all versions up to, and including, 3.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers,… | |
| Analizada | Media (6.1) | 0.45% | — | Msaad1999 Klik Socialmediawebsite | 29/2/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious JavaScript into the web browser of a victim via the poll parameter in poll.php. | |
| Analizada | Media (6.1) | 0.55% | — | Msaad1999 Klik Socialmediawebsite | 29/2/2024 | 17/6/2026 | KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may allow remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' or 'validator' parameters of 'create-new-pwd.php'. | |
| Analizada | Media (5.4) | 0.46% | — | Msaad1999 Klik Socialmediawebsite | 29/2/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parameter in offer.php. | |
| Modificada | Media (6.4) | 0.47% | — | Heateor Sassy Social Share | 29/2/2024 | 17/6/2026 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.3.56 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.1) | 0.35% | — | Socialdriver | 23/2/2024 | 17/6/2026 | The SocialDriver WordPress theme before version 2024 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties resulting in a cross-site scripting (XSS) attack. | |
| Modificada | Media (5.4) | 0.32% | — | Heateor Social Login | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress allows Stored XSS.This issue affects Heateor Social Login WordPress: from n/a through 1.1.30. | |
| Modificada | Alta (8.8) | 0.33% | — | Giovambattistafazioli WP Social Bookmark Menu | 29/1/2024 | 17/6/2026 | The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |
| Modificada | Media (4.8) | 0.30% | — | Mekshq Meks Smart Social Widget | 27/1/2024 | 17/6/2026 | The Meks Smart Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meks Smart Social Widget in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… |