Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
721 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.27% | — | Fobybus Social-media-skeleton | 18/8/2023 | 17/6/2026 | Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. A Cross-site request forgery (CSRF) attack is a type of malicious attack whereby an attacker tricks a victim into performing an action on a website that they do not intend to do. This can be done… | |
| Modificada | Media (4.8) | 0.37% | — | Supito Mahato Simple Light Weight Social Share | 10/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sudipto Pratap Mahato Simple Light Weight Social Share plugin <= 2.0 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Brandid Social Proof (testimonial) Slider | 10/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in brandiD Social Proof (Testimonial) Slider plugin <= 2.2.3 versions. | |
| Modificada | Media (5.4) | 0.49% | — | Fobybus Social-media-skeleton | 8/8/2023 | 17/6/2026 | social-media-skeleton is an uncompleted social media project implemented using PHP, MySQL, CSS, JavaScript, and HTML. Versions 1.0.0 until 1.0.3 have a stored cross-site scripting vulnerability. The problem is patched in v1.0.3. | |
| Modificada | Media (6.1) | 0.39% | — | Moosocial Mootravel | 6/8/2023 | 17/6/2026 | A vulnerability was found in mooSocial mooTravel 3.1.8 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-236210 is the identifier assigned to this vulnerability. | |
| Modificada | Media (6.1) | 9.1% | 💥 Exploit | Moosocial Moostore | 6/8/2023 | 17/6/2026 | A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The identifier VDB-236209 was assigned to this vulnerability. | |
| Modificada | Media (6.1) | 5.4% | 💥 Exploit | Moosocial Moostore | 6/8/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in mooSocial mooStore 3.1.6. Affected is an unknown function of the file /search/index. The manipulation of the argument q leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236208. | |
| Modificada | Alta (8.8) | 1.5% | — | Fobybus Social-media-skeleton | 4/8/2023 | 17/6/2026 | social-media-skeleton is an uncompleted social media project. A SQL injection vulnerability in the project allows UNION based injections, which indirectly leads to remote code execution. Commit 3cabdd35c3d874608883c9eaf9bf69b2014d25c1 contains a fix for this issue. | |
| Modificada | Media (4.3) | 0.61% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+6 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.5) | 0.69% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+7 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,… | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Moosocial Moodating | 23/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in mooSocial mooDating 1.2. Affected is an unknown function of the file /find-a-match of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is… | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Moosocial Moodating | 23/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in mooSocial mooDating 1.2. This issue affects some unknown processing of the file /users/view of the component URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this… | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Moosocial Moodating | 23/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in mooSocial mooDating 1.2. This vulnerability affects unknown code of the file /users of the component URL Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. VDB-235198 is the identifier assigned to this vulnerability.… | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Moosocial Moodating | 23/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in mooSocial mooDating 1.2. This affects an unknown part of the file /pages of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235197 was assigned to this… | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Moosocial Moodating | 23/7/2023 | 17/6/2026 | A vulnerability was found in mooSocial mooDating 1.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /friends/ajax_invite of the component URL Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The identifier of this… | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Moosocial Moodating | 23/7/2023 | 17/6/2026 | A vulnerability was found in mooSocial mooDating 1.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /friends of the component URL Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The associated identifier of this… | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Moosocial Moodating | 23/7/2023 | 17/6/2026 | A vulnerability was found in mooSocial mooDating 1.2. It has been classified as problematic. Affected is an unknown function of the file /matchmakings/question of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. VDB-235194 is the identifier… | |
| Modificada | Crítica (9.8) | 0.45% | — | GSS Vitals Enterprise Social Platform | 21/7/2023 | 17/6/2026 | Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0. | |
| Modificada | Alta (8.8) | 0.26% | — | Social Media Icons Widget Project Social Media Icons Widget | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in akhlesh-nagar, a.Ankit Social Media Icons Widget plugin <= 1.6 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | WP Social Autoconnect Project WP Social Autoconnect | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Justin Klein WP Social AutoConnect plugin <= 4.6.1 versions. | |
| Modificada | Media (4.3) | 0.48% | — | Slickremix Feed Them Social | 1/7/2023 | 17/6/2026 | The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the my_fts_fb_load_more() function. This makes it possible for unauthenticated attackers to… | |
| Modificada | Crítica (9.8) | 46% | 💥 Exploit | Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) | 29/6/2023 | 17/6/2026 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for… | |
| Modificada | Media (4.8) | 0.48% | — | Ultimatelysocial USM Premium | 27/6/2023 | 17/6/2026 | The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Media (5.4) | 0.42% | — | Heateor Super Socializer | 20/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor Super Socializer plugin <= 7.13.52 versions. | |
| Modificada | Alta (8.8) | 2.3% | 💥 Exploit | WP Sticky Social Project WP Sticky Social | 20/6/2023 | 17/6/2026 | The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation in the ~/admin/views/admin.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web… |