Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.31% | — | Ciphercoin Easy Hide Login | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Arshid Easy Hide Login.This issue affects Easy Hide Login: from n/a through 1.0.8. | |
| Modificada | Media (6.1) | 0.20% | — | Auto Login NEW User After Registration Project Auto Login NEW User After Registration | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Auto Login New User After Registration allows Stored XSS.This issue affects Auto Login New User After Registration: from n/a through 1.9.6. | |
| Modificada | Alta (8.8) | 0.30% | — | LWS Hide Login | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Hide Login plugin <= 2.1.6 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Featherplugins Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Nazmulhossainnihal Login Screen Manager | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) leading to a Stored Cross-Site Scripting (XSS) vulnerability in Nazmul Hossain Nihal Login Screen Manager plugin <= 3.5.2 versions. | |
| Modificada | Media (4.8) | 0.38% | — | Login Screen Manager Project Login Screen Manager | 31/10/2023 | 17/6/2026 | The Login Screen Manager WordPress plugin through 3.5.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (8.8) | 0.28% | — | Auto Login NEW User After Registration Project Auto Login NEW User After Registration | 25/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Auto Login New User After Registration plugin <= 1.9.6 versions. | |
| Modificada | Crítica (9.8) | 0.81% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 16/10/2023 | 17/6/2026 | SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page. | |
| Modificada | Media (5.4) | 0.37% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 16/10/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the user registration page. | |
| Modificada | Media (6.5) | 1.0% | 💥 PoC | Wpdo Dologin Security | 16/10/2023 | 17/6/2026 | The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users. | |
| Modificada | Alta (8.8) | 0.21% | — | Wpdoctor Woocommerce Login Redirect | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Doctor WooCommerce Login Redirect plugin <= 2.2.4 versions. | |
| Modificada | Crítica (9.8) | 0.95% | — | Knowband ONE Page Checkout, Social Login & Mailchimp | 5/10/2023 | 17/6/2026 | SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component. | |
| Analizada | Media (5.3) | 0.71% | 💥 PoC | Wpdo Dologin Security | 25/9/2023 | 17/6/2026 | The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing. | |
| Analizada | Media (6.1) | 0.70% | 💥 PoC | Wpdo Dologin Security | 25/9/2023 | 17/6/2026 | The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form. | |
| Modificada | Media (6.1) | 0.83% | — | Msaad1999 Php-login-system | 20/9/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'. | |
| Modificada | Media (6.1) | 0.88% | 💥 Exploit | Msaad1999 Php-login-system | 20/9/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'validator' parameter in '/reset-password'. | |
| Modificada | Alta (8.8) | 0.41% | — | Idehweb Login With Phone Number | 13/9/2023 | 17/6/2026 | The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function. This makes it possible for unauthenticated attackers to change user password via a forged request… | |
| Modificada | Alta (7.5) | 0.81% | — | Jenkins Google Login | 6/9/2023 | 17/6/2026 | Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token. | |
| Modificada | Media (4.8) | 0.37% | — | Custom Admin Login Page | Wpzest Plugin | 6/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPZest Custom Admin Login Page | WPZest plugin <= 1.2.0 versions. | |
| Modificada | Media (6.4) | 0.42% | — | Wordpress Social Login Project Wordpress Social Login | 6/9/2023 | 17/6/2026 | The WordPress Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wordpress_social_login_meta' shortcode in versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Media (4.8) | 0.44% | — | Miled Wordpress Social Login | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <= 3.0.4 versions. | |
| Modificada | Media (6.1) | 0.45% | — | Miled Wordpress Social Login | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <= 3.0.4 versions. | |
| Modificada | Media (6.1) | 0.37% | — | Login Configurator Project Login Configurator | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions. | |
| Modificada | Media (4.8) | 0.40% | — | Ciphercoin Easy Hide Login | 23/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Arshid Easy Hide Login plugin <= 1.0.7 versions. | |
| Analizada | Alta (7.5) | 0.84% | — | Wpexperts ALL IN ONE Login | 21/8/2023 | 17/6/2026 | The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered. |