Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.31% | — | Adamsolymosi Contentlock | 12/7/2024 | 17/6/2026 | The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (5.4) | 0.31% | — | Matteoenna Website Content IN Page OR Post | 12/7/2024 | 17/6/2026 | The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.8) | 0.37% | — | Ays-pro Secure Copy Content Protection AND Content Locking | 11/7/2024 | 17/6/2026 | The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Analizada | Media (6.1) | 0.39% | — | Magazine3 Easy Table OF Contents | 9/7/2024 | 17/6/2026 | The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. | |
| Analizada | Media (5.9) | 0.33% | — | Magazine3 Easy Table OF Contents | 26/6/2024 | 17/6/2026 | The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Analizada | Media (4.6) | 0.34% | — | Theluckywp Luckywp Table OF Contents | 14/6/2024 | 17/6/2026 | The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.3) | 0.35% | — | WP Dummy Content Generator Project WP Dummy Content Generator | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 2.3.0. | |
| Aplazada | Media (6.5) | 0.44% | — | If-so Dynamic Content PersonalizationAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in If So Plugin If-So Dynamic Content Personalization.This issue affects If-So Dynamic Content Personalization: from n/a through 1.7.1. | |
| Modificada | Alta (8.8) | 0.31% | — | Evergreencontentposter Evergreen Content Poster | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster.This issue affects Evergreen Content Poster: from n/a through <= 1.4.2. | |
| Aplazada | Media (4.3) | 0.28% | — | Ays-pro Secure Copy Content Protection AND Content LockingAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 3.7.1. | |
| Modificada | Media (5.4) | 0.20% | — | Elearningfreak Insert OR Embed Articulate Content | 4/6/2024 | 17/6/2026 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page. | |
| Aplazada | Media (4.3) | 0.34% | — | Pluginever WP Content PilotAI | 4/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in pluginever WP Content Pilot – Autoblogging & Affiliate Marketing Plugin allows Code Injection.This issue affects WP Content Pilot – Autoblogging & Affiliate Marketing Plugin: from n/a through 1.3.3. | |
| Analizada | Media (5.4) | 0.94% | 💥 PoC | Elearningfreak Insert OR Embed Articulate Content | 4/6/2024 | 17/6/2026 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files | |
| Modificada | Media (5.4) | 0.31% | — | Vanderwijk Content Blocks | 1/6/2024 | 17/6/2026 | The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_block' shortcode in all versions up to, and including, 3.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.62% | — | Vanderwijk Content Blocks | 1/6/2024 | 17/6/2026 | The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the plugin's 'content_block' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files… | |
| Aplazada | Media (5.4) | 0.27% | — | Doublesharp Remote Content ShortcodeAI | 30/5/2024 | 17/6/2026 | The Remote Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'remote_content' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (4.8) | 0.33% | — | Theluckywp Luckywp Table OF Contents | 22/5/2024 | 17/6/2026 | The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Contributor permissions and above to inject… | |
| Modificada | Media (6.1) | 0.38% | — | Theluckywp Luckywp Table OF Contents | 22/5/2024 | 17/6/2026 | The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs parameter in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Media (5.4) | 0.30% | — | Theluckywp Luckywp Table OF Contents | 22/5/2024 | 17/6/2026 | The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title' field in all versions up to and including 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Aplazada | Media (6.5) | 0.59% | — | Doublesharp Remote Content ShortcodeAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Justin Silver Remote Content Shortcode allows PHP Local File Inclusion.This issue affects Remote Content Shortcode: from n/a through 1.5. | |
| Aplazada | Media (6.4) | 0.35% | — | Contentviewspro Content ViewsAI | 14/5/2024 | 17/6/2026 | The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pagingType’ parameter in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (5.9) | 0.43% | — | Ieplexus Featured Content GalleryAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iePlexus Featured Content Gallery allows Stored XSS.This issue affects Featured Content Gallery: from n/a through 3.2.0. | |
| Aplazada | Alta (8.8) | 0.87% | 💥 PoC | JIN Fang Times Content Management SystemAI | 14/5/2024 | 17/6/2026 | Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter. | |
| Aplazada | Media (6.1) | 0.40% | — | Oxygen XML WEB AuthorAIOxygen Content FusionAI | 14/5/2024 | 17/6/2026 | Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting (XSS) for malicious URLs. | |
| Modificada | Media (5.4) | 0.25% | — | Vanderwijk Content Blocks | 8/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk Content Blocks (Custom Post Widget) allows Stored XSS.This issue affects Content Blocks (Custom Post Widget): from n/a through 3.3.0. |