Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
430 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.47% | — | Accordion Shortcodes Project Accordion Shortcodes | 30/1/2023 | 17/6/2026 | The Accordion Shortcodes WordPress plugin through 2.4.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Media (5.4) | 0.39% | — | Youtube Shortcode Project Youtube Shortcode | 23/1/2023 | 17/6/2026 | Auth. Stored Cross-Site Scripting (XSS) vulnerability in Youtube shortcode <= 1.8.5 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Easy Bootstrap Shortcode Project Easy Bootstrap Shortcode | 23/1/2023 | 17/6/2026 | The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Modificada | Media (5.4) | 0.47% | — | Codelights-shortcodes-and-widgets Project Codelights-shortcodes-and-widgets | 16/1/2023 | 17/6/2026 | The Sidebar Widgets by CodeLights WordPress plugin through 1.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege… | |
| Modificada | Media (4.8) | 0.56% | — | Codelights-shortcodes-and-widgets Project Codelights-shortcodes-and-widgets | 20/12/2022 | 17/6/2026 | The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS class’ parameter in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Modificada | Alta (8.8) | 0.76% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 12/12/2022 | 17/6/2026 | The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | |
| Modificada | Alta (8.8) | 0.33% | — | Getshortcodes Shortcodes Ultimate | 8/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress. | |
| Modificada | Media (4.3) | 0.32% | — | Getshortcodes Shortcodes Ultimate | 11/10/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shortcodes Ultimate plugin <= 5.12.0 at WordPress leading to plugin preset settings change. | |
| Modificada | Media (4.8) | 0.58% | — | Wpchill CPO Shortcodes | 23/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CPO Shortcodes plugin <= 1.5.0 at WordPress. | |
| Modificada | Media (4.8) | 0.68% | — | ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters | 23/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability Add Shortcodes Actions And Filters plugin <= 2.0.9 at WordPress. | |
| Modificada | Alta (7.2) | 1.2% | — | Oxilab Shortcode Addons | 27/7/2022 | 17/6/2026 | Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress. | |
| Modificada | Media (5.3) | 3.3% | — | Oxilab Shortcode Addons | 21/7/2022 | 17/6/2026 | Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress. | |
| Modificada | Media (6.1) | 1.4% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 11/7/2022 | 17/6/2026 | The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.80% | — | Custom Tinymce Shortcode Button Project Custom Tinymce Shortcode Button | 16/5/2022 | 17/6/2026 | The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting. | |
| Modificada | Media (5.4) | 0.60% | — | Custom Content Shortcode Project Custom Content Shortcode | 7/3/2022 | 17/6/2026 | The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. Please note that such attack is still possible by… | |
| Modificada | Media (4.3) | 0.44% | — | Custom Content Shortcode Project Custom Content Shortcode | 7/3/2022 | 17/6/2026 | The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such as logs, .htaccess etc), as well as perform Local File Inclusion attacks as PHP… | |
| Modificada | Media (4.3) | 0.79% | — | Custom Content Shortcode Project Custom Content Shortcode | 7/3/2022 | 17/6/2026 | The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of… | |
| Modificada | Media (4.3) | 0.81% | — | User Meta Shortcodes Project User Meta Shortcodes | 13/12/2021 | 17/6/2026 | The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes | |
| Modificada | Media (4.3) | 0.81% | — | Page/post Content Shortcode Project Page/post Content Shortcode | 13/12/2021 | 17/6/2026 | The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors. | |
| Modificada | Media (5.4) | 0.62% | — | Getshortcodes Shortcodes Ultimate | 20/9/2021 | 17/6/2026 | The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like… | |
| Modificada | Media (6.1) | 3.9% | — | Visualshortcodes Ninja | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter. | |
| Modificada | Media (6.5) | 0.87% | — | Olevmedia Shortcodes | 26/9/2019 | 17/6/2026 | The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter. | |
| Modificada | Crítica (9.8) | 2.0% | — | Wpmadeasy Shortcode Factory | 22/8/2019 | 17/6/2026 | The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion. | |
| Modificada | Crítica (9.8) | 12% | — | Getshortcodes Shortcodes Ultimate | 22/8/2019 | 17/6/2026 | The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode. | |
| Modificada | Media (6.1) | 0.91% | — | Wpmadeeasy Shortcode Factory | 21/8/2019 | 17/6/2026 | The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg. |