Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.54% | — | Themepoints TAB Ultimate | 22/11/2023 | 17/6/2026 | The Tab Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Modificada | Media (4.8) | 0.38% | — | Davidvongries Ultimate Dashboard | 22/11/2023 | 17/6/2026 | The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.7.7. due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (6.5) | 0.49% | — | Getshortcodes Shortcodes Ultimate | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6. | |
| Modificada | Alta (8.8) | 0.31% | — | Wpmet WP Ultimate Review | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions. | |
| Modificada | Media (5.4) | 0.31% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 27/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 versions. | |
| Modificada | Media (6.1) | 0.44% | — | Xydac Ultimate Taxonomy Manager | 25/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XYDAC Ultimate Taxonomy Manager plugin <= 2.0 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Wpmet WP Ultimate Review | 22/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions. | |
| Modificada | Alta (8.8) | 0.22% | — | Ultimatelysocial Social Media Share Buttons & Social Sharing Icons | 20/10/2023 | 17/6/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This makes it possible for unauthenticated… | |
| Modificada | Media (6.5) | 1.2% | 💥 PoC | Ultimatelysocial Social Media Share Buttons & Social Sharing Icons | 20/10/2023 | 17/6/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well… | |
| Modificada | Alta (8.8) | 0.58% | — | Easyuse Mailhunter Ultimate | 17/10/2023 | 17/6/2026 | SQL Injection in create customer group function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to execute arbitrary SQL commands via the ctl00$ContentPlaceHolder1$txtCustSQL parameter. | |
| Modificada | Media (4.3) | 0.43% | — | Easyuse Mailhunter Ultimate | 17/10/2023 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to obtain the absolute path via unencrypted VIEWSTATE parameter. | |
| Modificada | Media (6.5) | 0.64% | — | Easyuse Mailhunter Ultimate | 17/10/2023 | 17/6/2026 | Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to extract files into arbitrary directories via a crafted ZIP archive. | |
| Modificada | Alta (8.8) | 0.65% | — | Easyuse Mailhunter Ultimate | 17/10/2023 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate 2023 and earlier allows remote authenticated users to perform arbitrary system commands with ‘NT Authority\SYSTEM‘ privilege via a crafted ZIP archive. | |
| Modificada | Alta (8.8) | 0.21% | — | Xydac Ultimate Taxonomy Manager | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in XYDAC Ultimate Taxonomy Manager plugin <= 2.0 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Ultimatelysocial Social Media Share Buttons & Social Sharing Icons | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UltimatelySocial Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.3 versions. | |
| Modificada | Media (6.1) | 0.39% | — | Themefic Ultimate Addons FOR Contact Form 7 | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2.0 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Essentialplugin Audio Player With Playlist Ultimate | 3/9/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Audio Player with Playlist Ultimate plugin <= 1.2.2 versions. | |
| Modificada | Media (6.1) | 0.49% | — | Themefic Ultimate Addons FOR Contact Form 7 | 14/8/2023 | 17/6/2026 | The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (4.8) | 0.47% | — | Themefic Ultimate Addons FOR Contact Form 7 | 14/8/2023 | 17/6/2026 | The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 1.6% | — | Smackcoders WP Ultimate CSV Importer | 4/8/2023 | 17/6/2026 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to execute code… | |
| Modificada | Alta (8.8) | 1.6% | — | Smackcoders WP Ultimate CSV Importer | 4/8/2023 | 17/6/2026 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to create a PHP… | |
| Modificada | Alta (8.8) | 0.79% | — | Smackcoders WP Ultimate CSV Importer | 4/8/2023 | 17/6/2026 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_values' function. This makes it possible for authenticated attackers, with minimal permissions such as an author, if the administrator… | |
| Modificada | Alta (7.5) | 0.68% | — | Smackcoders WP Ultimate CSV Importer | 4/8/2023 | 17/6/2026 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction in export folder indexing in versions up to, and including, 7.9.8. This makes it possible for unauthenticated attackers to list and view exported files. | |
| Modificada | Media (4.3) | 0.61% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+6 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.5) | 0.69% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+7 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,… |