Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.26% | — | Ersatzpole ML Responsive Audio Player With Playlist ShortcodeAI | 11/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ersatzpole ML Responsive Audio player with playlist Shortcode mlr-audio allows Stored XSS.This issue affects ML Responsive Audio player with playlist Shortcode: from n/a through <= 0.2. | |
| Aplazada | Media (6.4) | 0.34% | — | Tipsandtricks-hq Compact WP Audio PlayerAI | 24/10/2024 | 17/6/2026 | The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_embed_player shortcode in all versions up to, and including, 1.9.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Alta (8.1) | 19% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 29/8/2024 | 17/6/2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1.… | |
| Modificada | Media (5.4) | 0.26% | — | Bplugins Html5 Audio Player | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.2.23. | |
| Modificada | Media (5.4) | 0.33% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 10/7/2024 | 17/6/2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on user… | |
| Aplazada | Media (6.4) | 0.46% | — | Bplugins Html5 Audio PlayerAI | 14/5/2024 | 17/6/2026 | The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.2.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (7.5) | 0.55% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 10/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1. | |
| Modificada | Media (5.4) | 0.34% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1. | |
| Modificada | Alta (7.6) | 0.48% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 29/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1. | |
| Aplazada | Media (6.5) | 0.32% | — | Tipsandtricks-hq Compact WP Audio PlayerAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Compact WP Audio Player allows Stored XSS.This issue affects Compact WP Audio Player: from n/a through 1.9.9. | |
| Modificada | Alta (8.8) | 0.44% | — | Mekshq Meks Audio PlayerMekshq Meks Easy ADS WidgetMekshq Meks Easy MapsMekshq Meks Easy Photo Feed Widget+6 | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the… | |
| Modificada | Media (5.4) | 0.36% | — | Essentialplugin Audio Player With Playlist Ultimate | 3/9/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Audio Player with Playlist Ultimate plugin <= 1.2.2 versions. | |
| Modificada | Media (5.4) | 0.57% | — | Bplugins Html5 Audio Player | 6/2/2023 | 17/6/2026 | The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.47% | — | Tipsandtricks-hq Compact WP Audio Player | 23/1/2023 | 17/6/2026 | The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Media (4.8) | 0.64% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 1/11/2021 | 17/6/2026 | The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks | |
| Modificada | Media (6.5) | 0.57% | — | Tipsandtricks-hq Compact WP Audio Player | 18/10/2021 | 17/6/2026 | The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack. | |
| Modificada | Media (5.4) | 0.65% | — | Tipsandtricks-hq Compact WP Audio Player | 18/10/2021 | 17/6/2026 | The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.65% | — | Bplugins Html5 Audio Player | 18/10/2021 | 17/6/2026 | The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode | |
| Modificada | Media (5) | 19% | — | SE Html5 Album Audio Player Project SE Html5 Album Audio Player | 17/6/2015 | 17/6/2026 | Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player) plugin 1.1.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (4.3) | 4.2% | — | Magic Hills Wonderplugin Audio Player | 5/3/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) item[name] or (2) item[customcss] parameter in a… | |
| Modificada | Media (6.5) | 2.6% | — | Wonderplugin Audio Player | 3/3/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or remote administrators to execute arbitrary SQL… | |
| Modificada | Media (4.3) | 6.4% | — | Doryphores Audio Player | 7/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter. | |
| Modificada | Alta (9.3) | 6.8% | — | Mercuryaudio Audio Player | 29/3/2010 | 16/6/2026 | Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .b4s or (2) .pls playlist file. | |
| Modificada | Alta (9.3) | 6.0% | — | Mercuryaudio Audio Player | 29/3/2010 | 16/6/2026 | Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. | |
| Modificada | Alta (9.3) | 5.8% | — | Malsmith Serenity Audio Player | 29/11/2009 | 16/6/2026 | Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote attackers to execute arbitrary code via a long URL in an M3U file. NOTE: some of these details are obtained from third party information. |