Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.35% | — | I13websolution Video Carousel Slider With Lightbox | 25/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution video carousel slider with lightbox plugin <= 1.0.22 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Tridenttechnolabs Easy Slider Revolution | 17/8/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Trident Technolabs Easy Slider Revolution plugin <= 1.0.0 versions. | |
| Modificada | Media (5.4) | 0.37% | — | Web-settler Layer Slider | 10/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Brandid Social Proof (testimonial) Slider | 10/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in brandiD Social Proof (Testimonial) Slider plugin <= 2.2.3 versions. | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Wordpress Vertical Image Slider | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WordPress vertical image slider plugin <= 1.2.16 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Recent Posts Slider Project Recent Posts Slider | 25/7/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Neha Goel Recent Posts Slider plugin <= 1.1 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Vibethemes Vslider | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 versions. | |
| Modificada | Media (4.3) | 0.39% | — | Quantumcloud Slider Hero | 12/7/2023 | 17/6/2026 | The Slider Hero plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.0. This is due to missing or incorrect nonce validation on the qc_slider_hero_duplicate() function. This makes it possible for unauthenticated attackers to duplicate slides via a forged request… | |
| Modificada | Media (6.5) | 0.22% | — | Recent Posts Slider Project Recent Posts Slider | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Neha Goel Recent Posts Slider plugin <= 1.1 versions. | |
| Modificada | Media (6.5) | 0.26% | — | Web-settler Layer Slider | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions. | |
| Modificada | Alta (8.8) | 2.5% | — | Themepunch Slider Revolution | 19/6/2023 | 17/6/2026 | The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations. | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Team Circle Image Slider With Lightbox | 9/6/2023 | 17/6/2026 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Wordpress Vertical Image Slider | 9/6/2023 | 17/6/2026 | The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Crítica (9.8) | 0.67% | — | Joommasters JMS Slider | 5/6/2023 | 17/6/2026 | PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php. | |
| Modificada | Alta (8.8) | 0.26% | — | Codeixer Product Gallery Slider FOR Woocommerce | 29/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Codeixer Product Gallery Slider for WooCommerce plugin <= 2.2.8 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Ljapps WP Airbnb Review Slider | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LJ Apps WP Airbnb Review Slider plugin <= 3.2 versions. | |
| Modificada | Media (6.1) | 0.61% | — | I13websolution Video Carousel Slider With Lightbox | 16/5/2023 | 17/6/2026 | The video carousel slider with lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (6.1) | 0.48% | — | I13websolution Thumbnail Carousel Slider | 15/5/2023 | 17/6/2026 | The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting vulnerability which could be used against high privilege users such as admin. | |
| Modificada | Media (4.8) | 0.37% | — | Gopiplus Tiny Carousel Horizontal Slider Plus | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Tiny carousel horizontal slider plus plugin <= 3.2 versions. | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Full Width Banner Slider WP | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Full Width Banner Slider Wp plugin <= 1.1.7 versions. | |
| Modificada | Media (5.4) | 0.37% | — | Wpmart Team Member - Team With Slider | 9/5/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Sk. Abul Hasan Team Member – Team with Slider plugin <= 4.4 versions. | |
| Modificada | Media (5.4) | 0.50% | — | Shapedplugin Product Slider FOR Woocommerce | 8/5/2023 | 17/6/2026 | The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Easy Testimonial Slider AND Form | 8/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form plugin <= 1.0.15 versions. | |
| Analizada | Media (4.8) | 0.37% | — | Vibethemes Vslider | 3/5/2023 | 17/6/2026 | Auth. Stored Cross-Site Scripting (XSS) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 versions. | |
| Modificada | Media (6.1) | 0.60% | — | I13websolution Thumbnail Carousel Slider | 18/4/2023 | 17/6/2026 | The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… |