Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
721 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.45% | — | Code-projects Social Networking Site | 19/1/2024 | 17/6/2026 | A vulnerability was found in code-projects Social Networking Site 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file message.php of the component Message Page. The manipulation of the argument Story leads to cross site scripting. The attack may be launched remotely. The… | |
| Modificada | Media (6.5) | 0.56% | — | Wpmet WP Social Login AND Register Social Counter | 19/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp Social Login and Register Social Counter: from n/a through 1.9.0. | |
| Modificada | Crítica (9.8) | 1.9% | — | Warfareplugins Social Warfare | 17/1/2024 | 17/6/2026 | The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server. | |
| Modificada | Media (4.8) | 0.50% | — | Seedwebs Seed Social | 16/1/2024 | 17/6/2026 | The Seed Social WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.5) | 0.49% | — | Leechesnutt Slick Social Share Buttons | 11/1/2024 | 17/6/2026 | The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dcssb_ajax_update' function in versions up to, and including, 2.4.11. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update… | |
| Modificada | Media (4.3) | 0.32% | — | Easysocialfeed Easy Social Feed | 11/1/2024 | 17/6/2026 | The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 6.5.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized… | |
| Modificada | Media (4.8) | 0.39% | — | Getsocial Social Share Buttons & Analytics | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Getsocial, S.A. Social Share Buttons & Analytics Plugin – GetSocial.Io allows Stored XSS.This issue affects Social Share Buttons & Analytics Plugin – GetSocial.Io: from n/a through 4.3.12. | |
| Modificada | Media (6.1) | 0.40% | — | Nextscripts Social Networks Auto Poster | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts: Social Networks Auto-Poster allows Reflected XSS.This issue affects NextScripts: Social Networks Auto-Poster: from n/a through 4.4.2. | |
| Modificada | Media (4.8) | 0.39% | — | Codebard Fast Custom Social Share | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard Fast Custom Social Share by CodeBard allows Stored XSS.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.1. | |
| Modificada | Media (5.4) | 0.38% | — | Cybernetikz Easy Social Icons | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cybernetikz Easy Social Icons allows Stored XSS.This issue affects Easy Social Icons: from n/a through 3.2.4. | |
| Modificada | Media (5.3) | 0.57% | — | Wpbrigade Simple Social Buttons | 27/11/2023 | 17/6/2026 | The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthenticated visitors in some meta tags | |
| Modificada | Alta (8.8) | 0.27% | — | Accesspressthemes Social Auto Poster | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes Social Auto Poster plugin <= 2.1.4 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Web-dorado Wdsocialwidgets | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions. | |
| Modificada | Alta (8.8) | 0.30% | — | Wbcomdesigns Buddypress Activity Social Share | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wbcom Designs Wbcom Designs – BuddyPress Activity Social Share plugin <= 3.5.0 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Superbthemes Superb Social Media Share Buttons AND Follow Buttons | 10/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SuPlugins Superb Social Media Share Buttons and Follow Buttons for WordPress plugin <= 1.1.3 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Vyasdipen TOP 25 Social Icons | 8/11/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vyas Dipen Top 25 Social Icons plugin <= 3.1 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Web-settler Social Feed | ALL Social Media IN ONE Place | 8/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Social Feed | All social media in one place plugin <= 1.5.4.6 versions. | |
| Modificada | Media (5.4) | 0.46% | — | Web-settler Social Feed | 7/11/2023 | 17/6/2026 | The Social Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialfeed' shortcode in all versions up to, and including, 1.5.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5.4) | 0.56% | 💥 PoC | Warfareplugins Social Warfare | 7/11/2023 | 17/6/2026 | The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Alta (8.8) | 0.65% | — | GSS Vitals Enterprise Social Platform | 3/11/2023 | 17/6/2026 | Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform… | |
| Modificada | Crítica (9.8) | 0.56% | — | Bontheme Socialfeed - Photos & Video Using Instagram API | 3/11/2023 | 17/6/2026 | Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at insta_parser.php. This vulnerability allows attackers to use the vulnerable website as proxy to attack other websites or exfiltrate data via a HTTP call. | |
| Modificada | Media (6.1) | 0.32% | — | Web-dorado Wdsocialwidgets | 26/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions. | |
| Modificada | Alta (8.8) | 0.22% | — | Ultimatelysocial Social Media Share Buttons & Social Sharing Icons | 20/10/2023 | 17/6/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This makes it possible for unauthenticated… | |
| Modificada | Media (6.5) | 1.2% | 💥 PoC | Ultimatelysocial Social Media Share Buttons & Social Sharing Icons | 20/10/2023 | 17/6/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well… | |
| Modificada | Media (4.3) | 0.59% | — | Adenion Blog2social | 20/10/2023 | 17/6/2026 | The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only. |