Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

53 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.48%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
ModificadaAlta (8.8)0.58%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
ModificadaAlta (8.8)0.44%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3.
ModificadaAlta (8.8)0.69%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
ModificadaAlta (8.8)0.46%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Code Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.
ModificadaAlta (8.8)0.69%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.3.
ModificadaAlta (8.5)0.47%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
ModificadaAlta (8.8)0.60%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.
ModificadaAlta (8.8)0.62%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3.
AnalizadaCrítica (9.8)35%💥 PoCVibethemes Wordpress Learning Management System9/11/202417/6/2026
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for…
AnalizadaMedia (5.4)0.32%—Muffingroup Betheme13/9/202417/6/2026
The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 27.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web…
AnalizadaMedia (5.4)0.26%—Muffingroup Betheme30/8/202417/6/2026
The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.8)0.62%—Muffingroup Betheme30/8/202417/6/2026
The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No…
AnalizadaAlta (7.2)0.46%—Muffingroup Betheme19/6/202417/6/2026
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1.
AnalizadaAlta (7.6)0.29%—Muffingroup Betheme19/6/202417/6/2026
Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1.
ModificadaAlta (8.8)0.54%—Muffingroup Betheme25/3/202417/6/2026
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.
ModificadaMedia (4.3)0.40%—Muffingroup Betheme25/3/202417/6/2026
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.
ModificadaMedia (5.4)0.46%—Muffingroup Betheme25/3/202417/6/2026
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.
ModificadaMedia (4.3)0.40%—Muffingroup Betheme25/3/202417/6/2026
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.
ModificadaAlta (8.8)0.26%—Vibethemes Vslider17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 versions.
AnalizadaAlta (8.8)0.30%—Vibethemes Wordpress Learning Management System11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions.
ModificadaCrítica (9.8)1.6%—Vibethemes BP Social Connect19/5/202317/6/2026
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on…
ModificadaMedia (6.1)0.38%—Muffingroup Betheme10/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Muffingroup Betheme theme <= 26.7.5 versions.
AnalizadaMedia (4.8)0.37%—Vibethemes Vslider3/5/202317/6/2026
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 versions.
ModificadaAlta (8.1)0.50%—Muffingroup Betheme14/1/202317/6/2026
Broken Access Control in Betheme theme <= 26.6.1 on WordPress.
Orbitaley — Vulnerabilidades