Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.45% | — | Peprodev Ultimate Invoice | 17/3/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 1.9.7. | |
| Aplazada | Media (5.3) | 0.27% | — | Wpsmartplugins Ultimate Gift CardsAI | 16/3/2024 | 17/6/2026 | The Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the wps_wgm_preview_email_template(). This makes it possible for unauthenticated… | |
| Modificada | Media (6.1) | 0.38% | — | Etoilewebdesign Ultimate Reviews | 15/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8. | |
| Analizada | Crítica (9.8) | 0.63% | — | Advancedplugins Ultimateimagetool | 14/3/2024 | 17/6/2026 | An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper Access Control. | |
| Modificada | Alta (8.8) | 1.2% | — | Wpwax Post Grid, Slider & Carousel Ultimate | 13/3/2024 | 17/6/2026 | The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.7 via deserialization of untrusted input in the outpost_shortcode_metabox_markup function. This makes it possible for… | |
| Aplazada | Alta (7.5) | 1.0% | — | Logo Showcase UltimateAI | 13/3/2024 | 17/6/2026 | The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8 via deserialization via shortcode of untrusted input. This makes it possible for authenticated attackers, with contributor access and above, to… | |
| Modificada | Alta (8.8) | 1.2% | — | Wpwax Product Carousel Slider & Grid Ultimate FOR Woocommerce | 13/3/2024 | 17/6/2026 | The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted input via shortcode. This makes it possible for authenticated attackers, with contributor access and above, to inject a PHP… | |
| Analizada | Crítica (9.8) | 89% | 💥 Exploit | Ultimatemember Ultimate Member | 13/3/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Modificada | Media (6.1) | 27% | — | Ultimatemember Ultimate Member | 13/3/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This… | |
| Analizada | Media (5.4) | 0.44% | — | Inisev Ultimate Posts Widget | 11/3/2024 | 17/6/2026 | The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for… | |
| Modificada | Media (6.4) | 0.51% | — | G5plus Ultimate Bootstrap Elements FOR Elementor | 2/3/2024 | 17/6/2026 | The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_title_tag’ and ’heading_sub_title_tag’ parameters in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Media (5.4) | 0.44% | — | Getshortcodes Shortcodes Ultimate | 29/2/2024 | 17/6/2026 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping on RSS feed content. This makes it possible for authenticated attackers… | |
| Modificada | Media (5.4) | 0.34% | — | Getshortcodes Shortcodes Ultimate | 28/2/2024 | 17/6/2026 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_qrcode' shortcode in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.4) | 0.47% | — | Getshortcodes Shortcodes Ultimate | 20/2/2024 | 17/6/2026 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_tooltip shortcode in all versions up to, and including, 7.0.2 due to insufficient input sanitization and output escaping on user supplied attributes and user supplied tags. This makes it… | |
| Modificada | Media (4.3) | 0.32% | — | Brainstormforce Ultimate Addons FOR Beaver Builder | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through 1.5.5. | |
| Modificada | Media (4.8) | 0.42% | — | Supsystic Ultimate Maps | 16/1/2024 | 17/6/2026 | The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (6.9) | 0.48% | — | Fairsketch Rise Ultimate Project Manager | 15/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the file /index.php/signin. The manipulation of the argument redirect with the input http://evil.com leads to open redirect. The attack can be initiated remotely. The… | |
| Modificada | Alta (8.8) | 0.22% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 29/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brain Storm Force Ultimate Addons for WPBakery Page Builder.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.17. | |
| Modificada | Media (4.8) | 0.40% | — | Davidvongries Ultimate Dashboard | 21/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard – Custom WordPress Dashboard: from n/a through 3.7.11. | |
| Modificada | Alta (8.1) | 0.63% | — | Themefic Ultimate Addons FOR Contact Form 7 | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Ultimate Addons for Contact Form 7.This issue affects Ultimate Addons for Contact Form 7: from n/a through 3.1.23. | |
| Modificada | Media (5.4) | 0.47% | — | Getshortcodes Shortcodes Ultimate | 19/12/2023 | 17/6/2026 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_button', 'su_members', and 'su_tabs' shortcodes in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Modificada | Media (6.1) | 0.40% | — | Themefic Ultimate Addons FOR Contact Form 7 | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate Addons for Contact Form 7 allows Stored XSS.This issue affects Ultimate Addons for Contact Form 7: from n/a through 3.2.0. | |
| Modificada | Media (5.4) | 0.30% | — | Addonmaster Bootstrap Shortcodes Ultimate | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akhtarujjaman Shuvo Bootstrap Shortcodes Ultimate allows Stored XSS.This issue affects Bootstrap Shortcodes Ultimate: from n/a through 4.3.1. | |
| Modificada | Media (4.3) | 0.53% | — | Getshortcodes Shortcodes Ultimate | 28/11/2023 | 17/6/2026 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys 'key' and 'post_id'. This makes it possible for authenticated attackers,… | |
| Modificada | Media (5.4) | 0.48% | — | Getshortcodes Shortcodes Ultimate | 28/11/2023 | 17/6/2026 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_meta shortcode combined with post meta data in all versions up to, and including, 5.13.3 due to insufficient input sanitization and output escaping on user supplied meta values. This… |