Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1807 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.26% | — | Otowthemes Post Custom Templates LiteAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Post Custom Templates Lite post-custom-templates-lite allows Stored XSS.This issue affects Post Custom Templates Lite: from n/a through <= 1.14. | |
| Aplazada | Media (5.3) | 0.32% | — | Centangle WOO Direct Checkout LiteAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite woo-direct-checkout-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Direct Checkout for WooCommerce Lite: from n/a through <= 1.0.3. | |
| Aplazada | Media (4.3) | 0.16% | — | Weblizar HR Management LiteAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Weblizar - WordPress Themes & Plugin HR Management Lite hr-management-lite allows Cross Site Request Forgery.This issue affects HR Management Lite: from n/a through <= 3.6. | |
| Aplazada | Media (5.3) | 0.34% | — | Webnus Modern Events Calendar LiteAI | 6/6/2025 | 17/6/2026 | The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Aplazada | Crítica (9.3) | 0.42% | — | Indigothemes WP HRM LiteAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IndigoThemes WP HRM LITE wp-hrm-lite-human-resource-management-system allows SQL Injection.This issue affects WP HRM LITE: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.29% | — | Chopluggins Custom PC Builder Lite FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ChoPlugins.com Custom PC Builder Lite for WooCommerce custom-pc-builder-lite-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.22% | — | Jinwen JS O3 LiteAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jinwen Js O3 Lite allows Reflected XSS.This issue affects Js O3 Lite: from n/a through 1.5.8.2. | |
| Aplazada | Media (5.4) | 0.14% | — | Redefiningtheweb Dynamic Pricing & Discounts Lite FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RedefiningTheWeb Dynamic Pricing & Discounts Lite for WooCommerce woo-dynamic-pricing-discounts-lite allows Cross Site Request Forgery.This issue affects Dynamic Pricing & Discounts Lite for WooCommerce: from n/a through <= 2.0.4. | |
| Aplazada | Media (6.5) | 0.20% | — | Saiful Islam Ultraaddons Elementor LiteAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam UltraAddons Elementor Lite ultraaddons-elementor-lite allows Stored XSS.This issue affects UltraAddons Elementor Lite: from n/a through <= 2.0.2. | |
| Aplazada | Media (5.3) | 0.33% | — | Ashan Perera Eventon LiteAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Ashan Perera EventON eventon-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects EventON: from n/a through <= 2.4.4. | |
| Analizada | Media (6.1) | 0.57% | 💥 Exploit | Codeflock WP Desklite | 15/5/2025 | 17/6/2026 | The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Baja (3.5) | 0.32% | — | Vk011 Real WP Shop Lite Ajax Ecommerce Shopping Cart | 15/5/2025 | 17/6/2026 | The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Aplazada | Alta (8.8) | 1.0% | — | Uipress LiteAI | 15/5/2025 | 17/6/2026 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.5.07 via the uip_process_form_input() function. This is due to the function taking user supplied inputs to execute arbitrary functions with… | |
| Aplazada | Media (6.4) | 0.23% | — | Weluka LiteAI | 15/5/2025 | 17/6/2026 | The Weluka Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'weluka-map' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (2.9) | 0.26% | — | Libsql Sqlite3 ParserAI | 9/5/2025 | 17/6/2026 | dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8. | |
| Aplazada | Alta (7.5) | 0.77% | — | Ashan Perera Eventon LiteAIMyeventon EventonAI | 7/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON eventon-lite allows PHP Local File Inclusion.This issue affects EventON: from n/a through <= 2.4.1. | |
| Aplazada | Media (5.3) | 0.40% | — | Wsform WS Form LiteAI | 25/4/2025 | 17/6/2026 | The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_config' function in all versions up to, and including, 1.10.35. This makes it possible for unauthenticated attackers to read the value of the… | |
| Aplazada | Crítica (9.3) | 0.52% | — | UNI Nms-liteAI | 24/4/2025 | 17/6/2026 | UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database. | |
| Aplazada | Crítica (9.3) | 0.55% | — | UI Uni-nms-liteAI | 24/4/2025 | 17/6/2026 | UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices. | |
| Aplazada | Crítica (9.3) | 2.0% | 💥 PoC | UNI Nms-liteAI | 24/4/2025 | 17/6/2026 | UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data. | |
| Aplazada | Media (4.3) | 0.15% | — | Codebangers ALL IN ONE Time Clock LiteAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Codebangers All in One Time Clock Lite aio-time-clock-lite allows Cross Site Request Forgery.This issue affects All in One Time Clock Lite: from n/a through < 1.3.326. | |
| Aplazada | Alta (7.5) | 0.75% | — | Codeworkweb Xews LiteAIPHPAI | 24/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codeworkweb Xews Lite xews-lite allows PHP Local File Inclusion.This issue affects Xews Lite: from n/a through <= 1.0.9. | |
| Analizada | Media (5.4) | 0.28% | — | Vjinfotech WP Import Export Lite | 22/4/2025 | 17/6/2026 | The WP Import Export Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpiePreviewData’ function in all versions up to, and including, 3.9.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (4.8) | 0.22% | — | Tokuhirom UnqliteAI | 18/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2. This vulnerability affects the function jx9MemObjStore of the file /data/src/benchmarks/unqlite/unqlite.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the… | |
| Analizada | Alta (7.2) | 0.50% | — | Litepublisher Litepubl CMS | 17/4/2025 | 17/6/2026 | Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run. |