Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1775 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.14% | — | Cimatti Contact FormsAI | 2/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in cimatti Contact Forms by Cimatti contact-forms allows Cross Site Request Forgery.This issue affects Contact Forms by Cimatti: from n/a through <= 1.9.8. | |
| Analizada | Media (4.3) | 0.22% | — | Mattermost Server | 30/5/2025 | 17/6/2026 | Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when… | |
| Analizada | Media (5.4) | 0.22% | — | Mattermost Server | 30/5/2025 | 17/6/2026 | Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens. | |
| Analizada | Media (4.2) | 0.21% | — | Mattermost Server | 30/5/2025 | 17/6/2026 | Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow. | |
| Analizada | Baja (3.1) | 0.24% | — | Mattermost Server | 30/5/2025 | 17/6/2026 | Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint. | |
| Analizada | Baja (3.8) | 0.31% | — | Mattermost Server | 29/5/2025 | 17/6/2026 | Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly validate permissions when changing team privacy settings, allowing team administrators without the 'invite user' permission to access and modify team invite IDs via the /api/v4/teams/:teamId/privacy endpoint. | |
| Aplazada | Media (6.1) | 0.33% | — | Marcomilesi WP AttachmentsAI | 28/5/2025 | 17/6/2026 | The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ parameter in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Alta (8.4) | 0.17% | — | Blizzard Battle.net | 21/5/2025 | 17/6/2026 | An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory. | |
| Modificada | Media (4.3) | 0.38% | — | Automattic Sensei LMS | 15/5/2025 | 17/6/2026 | The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page | |
| Analizada | Crítica (9.1) | 0.55% | — | Automattic Jetpack Boost | 15/5/2025 | 17/6/2026 | The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs. | |
| Analizada | Media (4.8) | 0.34% | — | Automattic Mailpoet | 15/5/2025 | 17/6/2026 | The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.9) | 0.30% | — | Automattic JetpackAutomattic Jetpack Boost | 15/5/2025 | 17/6/2026 | The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform… | |
| Analizada | Media (5.6) | 0.40% | — | Automattic Jetpack | 15/5/2025 | 17/6/2026 | The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block. | |
| Aplazada | Media (5.3) | 0.31% | — | Automattic Jetpack Debug ToolsAI | 15/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a before 2.0.1. | |
| Analizada | Baja (2.7) | 0.33% | — | Mattermost Server | 15/5/2025 | 17/6/2026 | Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true via System Console. | |
| Analizada | Media (4.3) | 0.30% | — | Mattermost Server | 15/5/2025 | 17/6/2026 | Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request. | |
| Analizada | Media (4.3) | 0.24% | — | Mattermost Server | 15/5/2025 | 17/6/2026 | Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct permissions which allows authenticated users who only have permission to invite non-guest users to a team to add guest users to that team via the API to add a single user to a team. | |
| Analizada | Media (5.3) | 0.34% | — | Mattermost Server | 15/5/2025 | 17/6/2026 | Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost. | |
| Analizada | Baja (3.3) | 0.22% | — | Matthewwithanm Markdownify | 26/4/2025 | 17/6/2026 | python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption. | |
| Aplazada | Alta (7.1) | 0.14% | — | Huangye Wudeng Hacklog Remote AttachmentAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment hacklog-remote-attachment allows Stored XSS.This issue affects Hacklog Remote Attachment: from n/a through <= 1.3.2. | |
| Aplazada | Alta (7.1) | 0.29% | — | BAS Matthee LSD Custom Taxonomy AND Category MetaAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bas Matthee LSD Custom taxonomy and category meta custom-taxonomy-category-and-term-fields allows Cross Site Request Forgery.This issue affects LSD Custom taxonomy and category meta: from n/a through <= 1.3.2. | |
| Aplazada | Media (6.5) | 0.27% | — | Matthew Muro Multi Column Taxonomy ListAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew Muro Multi-Column Taxonomy List multi-column-taxonomy-list allows Stored XSS.This issue affects Multi-Column Taxonomy List: from n/a through <= 1.5. | |
| Aplazada | Media (6.5) | 0.39% | — | Elex Woocommerce Advanced Bulk Edit Products Prices AttributesAI | 24/4/2025 | 17/6/2026 | The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value_filter' parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Analizada | Media (4.3) | 0.27% | — | Mattermost Server | 24/4/2025 | 17/6/2026 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or… | |
| Analizada | Alta (7.5) | 0.49% | — | Mattermost Server | 24/4/2025 | 17/6/2026 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web… |