Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2442 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | 8theme Xstore CoreAI8theme Et-core-pluginAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through <= 5.6.4. | |
| Aplazada | Crítica (9.8) | 0.38% | — | Fantasticplugins Sumo Affiliates PROAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0. | |
| Analizada | Alta (7.5) | 0.22% | — | Freedesktop Gst-plugins-goodGstreamerDebian LinuxRedhat Enterprise Linux | 23/3/2026 | 17/6/2026 | An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes… | |
| Aplazada | Alta (7.5) | 0.51% | — | Weplugins WP MapsAI | 23/3/2026 | 17/6/2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | |
| Aplazada | Media (6.1) | 0.43% | — | Alfie Feed PluginAI | 21/3/2026 | 17/6/2026 | The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the alfie_option_page() function combined with insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (6.4) | 0.24% | — | Tour Activity Operator Plugin FOR TourcmsAI | 21/3/2026 | 17/6/2026 | The Tour & Activity Operator Plugin for TourCMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the tourcms_doc_link shortcode in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.34% | — | Restrictcontent Membership Plugin Restrict ContentAI | 20/3/2026 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.2.24. This is due to insufficient validation on the redirect url supplied via the 'rcp_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users… | |
| Aplazada | Media (6.5) | 0.36% | — | Really-simple-plugins Really Simple Security PROAI | 19/3/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple Security Pro: from n/a through 9.5.4.0. | |
| Aplazada | Baja (2.3) | 0.53% | — | Openapi-to-java-records-mustache-templatesAIApache Maven-dependency-pluginAI | 18/3/2026 | 17/6/2026 | openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting in version 5.1.1 and prior to version 5.5.1, the parent POM file of this project (`openapi-to-java-records-mustache-templates-parent`), which is used to centralize plugin configurations for multiple… | |
| Aplazada | Media (4.3) | 0.23% | — | Wickedplugins Wicked FoldersAI | 16/3/2026 | 17/6/2026 | The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.26% | — | Really-simple-plugins Really Simple SSLAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple SSL: from n/a through <= 9.5.7. | |
| Aplazada | Media (6.5) | 0.22% | — | Pluginus Active Products Tables FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.7. | |
| Aplazada | Media (5.4) | 0.29% | — | Bplugins PDF PosterAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in bPlugins PDF Poster pdf-poster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF Poster: from n/a through <= 2.4.0. | |
| Aplazada | Media (5.9) | 0.24% | — | Richplugins Rich Showcase FOR Google ReviewsAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins Rich Showcase for Google Reviews widget-google-reviews allows Stored XSS.This issue affects Rich Showcase for Google Reviews: from n/a through <= 6.9.4.3. | |
| Aplazada | Media (6.5) | 0.22% | — | Bplugins Icon List BlockAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block icon-list-block allows Stored XSS.This issue affects Icon List Block: from n/a through <= 1.2.3. | |
| Analizada | Media (6.5) | 0.41% | — | Linuxfoundation Backstage/plugin-scaffolder-backend | 12/3/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Secrets are properly redacted in log output but not in all parts of the response… | |
| Aplazada | Media (6.1) | 0.29% | — | Plugin-planet Simple Ajax ChatAI | 12/3/2026 | 17/6/2026 | The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions up to, and including, 20260217 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Pendiente de análisis | Media (5) | 0.21% | — | SAP Solution Tools Plug-inAI | 10/3/2026 | 17/6/2026 | SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing system information to be disclosed. This vulnerability has a low impact on confidentiality and does not affect integrity or availability. | |
| Modificada | Crítica (9.8) | 0.95% | — | Linuxfoundation Backstage Plugin-techdocs-node | 7/3/2026 | 15/7/2026 | Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process.… | |
| Analizada | Media (6.5) | 0.30% | — | Linuxfoundation Backstage/plugin-scaffolder-backend | 7/3/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been patched in version 3.1.4. | |
| Aplazada | Media (4.7) | 0.29% | — | Kings Plugins B2bking PremiumAI | 6/3/2026 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This issue affects B2BKing Premium: from n/a before 5.4.20. | |
| Aplazada | Alta (8.1) | 0.36% | — | Membershipupplugin Membership Plugin Restrict ContentAI | 5/3/2026 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` function accepting any membership level ID via the `rcp_level` POST parameter without validating that the level is active… | |
| Aplazada | Alta (7.1) | 0.26% | — | E-plugins Lawyer DirectoryAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Lawyer Directory lawyer-directory allows Reflected XSS.This issue affects Lawyer Directory: from n/a through <= 1.3.2. | |
| Aplazada | Media (5.4) | 0.27% | — | Jp-secure Siteguard WP PluginAI | 5/3/2026 | 17/6/2026 | Guessable CAPTCHA vulnerability in jp-secure SiteGuard WP Plugin siteguard allows Functionality Bypass.This issue affects SiteGuard WP Plugin: from n/a through <= 1.7.9. | |
| Aplazada | Alta (7.3) | 0.31% | — | E-plugins Directory PROAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6. |