Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.42% | — | Express XSS Sanitizer Project Express XSS Sanitizer | 27/3/2026 | 17/6/2026 | Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack. A vulnerability has been identified in versions prior to 2.0.2 where restrictive sanitization configurations are silently ignored.… | |
| Analizada | Alta (8.2) | 0.18% | — | Botpress | 27/3/2026 | 18/8/2026 | The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it fetches user-controlled URLs ('MediaUrlN' parameters) using HTTP requests that include the integration's Twilio credentials in the 'Authorization' header. An attacker can… | |
| Aplazada | Media (6.1) | 0.27% | — | Floristpress FOR WOOAI | 26/3/2026 | 17/6/2026 | The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'noresults' parameter in all versions up to, and including, 7.8.2 due to insufficient input sanitization and output escaping on the user supplied 'noresults'… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Publishpress RevisionsAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Revisions revisionary allows Blind SQL Injection.This issue affects PublishPress Revisions: from n/a through <= 3.7.23. | |
| Aplazada | Alta (7.5) | 0.26% | — | Coderpress Commerce Coinbase FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in CoderPress Commerce Coinbase For WooCommerce commerce-coinbase-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Commerce Coinbase For WooCommerce: from n/a through <= 1.6.6. | |
| Aplazada | Alta (8.1) | 0.26% | — | Wordpresschef Salon Booking System PROAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12. | |
| Aplazada | Alta (7.5) | 0.29% | — | Publishpress AuthorsAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through <= 4.10.1. | |
| Aplazada | Alta (7.5) | 0.27% | — | Thimpress Learnpress Sepay PaymentAI | 25/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpress-sepay-payment allows Authentication Abuse.This issue affects LearnPress – Sepay Payment: from n/a through <= 4.0.0. | |
| Aplazada | Alta (7.5) | 0.35% | — | Blueglass Jobs FOR WordpressAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Jobs for WordPress: from n/a through <= 2.8. | |
| Aplazada | Alta (7.1) | 0.18% | — | Themepassion Ultra Wordpress AdminAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra WordPress Admin ultra-admin allows Reflected XSS.This issue affects Ultra WordPress Admin: from n/a through <= 11.7. | |
| Aplazada | Media (4.3) | 0.34% | — | Thimpress LearnpressAI | 23/3/2026 | 17/6/2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question answers due to a missing capability check in the delete_question_answer() function of the EditQuestionAjax class in all versions up to, and including, 4.3.2.8. The AbstractAjax::catch_lp_ajax() dispatcher… | |
| Aplazada | Media (6.9) | 0.13% | — | AdminexpressAI | 22/3/2026 | 17/6/2026 | AdminExpress 1.2.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the System Compare feature. Attackers can paste a large buffer of characters into the Folder Path field and trigger the comparison function to cause the application… | |
| Aplazada | Alta (8.5) | 0.14% | — | Admin ExpressAI | 22/3/2026 | 17/6/2026 | Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an alphanumeric encoded payload in the Folder Path field. Attackers can trigger the vulnerability through the System Compare feature by pasting a… | |
| Analizada | Alta (8.8) | 0.34% | — | Simplepresscms Simplepress CMS | 21/3/2026 | 17/6/2026 | SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'p' and 's' parameters. Attackers can send GET requests with crafted SQL payloads to extract sensitive database information including usernames,… | |
| Aplazada | Media (6.4) | 0.33% | — | Wordpress Paypal DonationAI | 21/3/2026 | 17/6/2026 | The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortcode in all versions up to, and including, 1.01. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'amount', 'email', 'title',… | |
| Aplazada | Media (6.5) | 0.41% | — | HR Press LiteAI | 21/3/2026 | 17/6/2026 | The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-fetch-employees` AJAX action in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (4.3) | 0.19% | — | Uipress LiteAI | 21/3/2026 | 17/6/2026 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_global_settings' function in all versions up to, and including, 3.5.09. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.53% | — | RockpressAI | 20/3/2026 | 17/6/2026 | The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. This is due to missing capability checks on multiple AJAX actions (rockpress_import, rockpress_import_status, rockpress_last_import, rockpress_reset_import, and rockpress_check_services) combined… | |
| Aplazada | Crítica (9.8) | 0.59% | — | Thimpress BuilderpressAIPHPAI | 19/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress builderpress allows PHP Local File Inclusion.This issue affects BuilderPress: from n/a through <= 2.0.1. | |
| Aplazada | Media (6.3) | 0.26% | — | Uipress LiteAI | 19/3/2026 | 17/6/2026 | Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UiPress lite: from n/a through <= 3.5.09. | |
| Aplazada | Baja (2.1) | 0.36% | — | Codegenieapp Serverless-expressAI | 16/3/2026 | 17/6/2026 | A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of the file examples/lambda-function-url/packages/api/models/TodoList.ts of the component API Endpoint. The manipulation of the argument userId leads to authorization bypass.… | |
| Aplazada | Media (5.4) | 0.14% | — | GamipressAI | 13/3/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garcia GamiPress gamipress allows Cross Site Request Forgery.This issue affects GamiPress: from n/a through <= 7.6.6. | |
| Aplazada | Media (5.4) | 0.22% | — | Giftup Gift UP Gift Cards FOR Wordpress AND WoocommerceAI | 13/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Gift Up! Gift Up Gift Cards for WordPress and WooCommerce gift-up allows Server Side Request Forgery.This issue affects Gift Up Gift Cards for WordPress and WooCommerce: from n/a through <= 3.1.7. | |
| Aplazada | Media (4.3) | 0.23% | — | Publishpress CapabilitiesAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Capabilities: from n/a through <= 2.31.0. | |
| Aplazada | Media (5.3) | 0.33% | — | Magepeopleteam WpeventlyAIMagepeopleteam Mage-eventpressAI | 13/3/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Retrieve Embedded Sensitive Data.This issue affects WpEvently: from n/a through < 5.1.9. |