Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.44% | — | WP Login BOX Project WP Login BOX | 8/5/2023 | 17/6/2026 | The WP Login Box WordPress plugin through 2.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.5) | 0.33% | — | Enable/disable Auto Login When Register Project Enable/disable Auto Login When Register | 8/5/2023 | 17/6/2026 | The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Crítica (9.8) | 0.77% | — | Php-login Project Php-login | 6/5/2023 | 17/6/2026 | A vulnerability was found in PHP-Login 1.0. It has been declared as critical. This vulnerability affects the function checkLogin of the file login/scripts/class.loginscript.php of the component POST Parameter Handler. The manipulation of the argument myusername leads to sql injection. The attack can be initiated… | |
| Modificada | Media (4.8) | 0.37% | — | Custom Login Page Project Custom Login Page | 4/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denzel Chia | Phire Design Custom Login Page plugin <= 2.0 versions. | |
| Modificada | Media (5.4) | 29% | — | Limit Login Attempts Project Limit Login Attempts | 2/5/2023 | 17/6/2026 | The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.8) | 0.37% | — | Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions. | |
| Modificada | Baja (3.3) | 0.22% | — | Pingidentity Pingid Integration FOR Windows Login | 25/4/2023 | 17/6/2026 | PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times. | |
| Modificada | Media (6.1) | 0.43% | — | Loginizer | 24/4/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Electric Studio Client Login Project Electric Studio Client Login | 23/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in James Irving-Swift Electric Studio Client Login plugin <= 0.8.1 versions. | |
| Modificada | Crítica (9.8) | 0.98% | — | ZM Ajax Login & Register Project ZM Ajax Login & Register | 15/4/2023 | 17/6/2026 | The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any… | |
| Modificada | Media (6.1) | 0.79% | — | Limit Login Attempts Project Limit Login Attempts | 6/4/2023 | 17/6/2026 | The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Alta (8.8) | 0.26% | — | Social Login WP Project Social Login WP | 16/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Social Login WP plugin <= 5.0.0.0 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Wpbrigade Login Logout Menu | 21/2/2023 | 17/6/2026 | The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Crítica (9.8) | 57% | 💥 Exploit | Sunlogin Sunflower | 13/2/2023 | 17/6/2026 | Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../ followed by the pathname of the… | |
| Modificada | Media (5.4) | 0.57% | — | Codection Clean Login | 6/2/2023 | 17/6/2026 | The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Media (5.4) | 0.53% | — | Wpbrigade Login Logout Menu | 23/1/2023 | 17/6/2026 | The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Crítica (9.8) | 39% | 💥 Exploit | Wp-buy Login AS User OR Customer (user Switching) | 23/1/2023 | 17/6/2026 | The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session. | |
| Modificada | Alta (7.5) | 0.70% | — | Ciphercoin WP Limit Login Attempts | 23/1/2023 | 17/6/2026 | The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based restrictions on login forms. | |
| Modificada | Alta (8.8) | 57% | 💥 Exploit | Idehweb Login With Phone Number | 20/1/2023 | 17/6/2026 | The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action. | |
| Modificada | Media (6.1) | 0.45% | — | Syracom Secure Login | 11/1/2023 | 17/6/2026 | The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target parameter. | |
| Modificada | Media (4.8) | 0.53% | — | Miniorange Login With Cognito | 2/1/2023 | 17/6/2026 | The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.54% | — | Wp-glogin Login FOR Google Apps | 26/12/2022 | 17/6/2026 | The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.1) | 0.56% | — | Jenkins Google Login | 12/12/2022 | 17/6/2026 | Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkins. | |
| Modificada | Alta (7.5) | 0.70% | — | Gunkastudios Login Block IPS | 21/11/2022 | 17/6/2026 | The function check_is_login_page() uses headers for the IP check, which can be easily spoofed. | |
| Modificada | Media (5.3) | 0.51% | — | Wpbrigade Loginpress | 18/11/2022 | 17/6/2026 | Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings. |