Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.35% | — | Bootstrapped Visual Link PreviewAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Brecht Visual Link Preview visual-link-preview allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visual Link Preview: from n/a through <= 2.2.9. | |
| Aplazada | Media (4.3) | 0.19% | — | Bootstrapped WP Recipe MakerAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Brecht WP Recipe Maker wp-recipe-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Recipe Maker: from n/a through <= 10.2.4. | |
| Aplazada | Media (4.3) | 0.35% | — | Bootstrapped WP Recipe MakerAI | 16/1/2026 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 via the api_get_post_summary function due to insufficient restrictions on which posts can be retrieved. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (6.5) | 0.19% | — | Neilgee Bootstrap ModalsAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in neilgee Bootstrap Modals bootstrap-modals allows Stored XSS.This issue affects Bootstrap Modals: from n/a through <= 1.3.2. | |
| Aplazada | Media (6.4) | 0.31% | — | Bootstrapped WP Recipe MakerAI | 17/12/2025 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 10.2.3 due to insufficient input sanitization and output escaping on user-supplied attributes in the wprm-recipe-roundup-item shortcode. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.18% | — | Shortcodes BootstrapAI | 21/11/2025 | 17/6/2026 | The Shortcodes Bootstrap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in the [notification] shortcode in all versions up to, and including, 1.1. This is due to missing input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.27% | — | WP Bootstrap TabsAI | 11/11/2025 | 17/6/2026 | The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcode in all versions up to, and including, 1.0.4. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.24% | — | Bootstrapped Visual Link PreviewAI | 5/11/2025 | 17/6/2026 | The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-preview shortcode in versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.4) | 0.23% | — | Bootstrap Multi Language Responsive PortfolioAI | 4/11/2025 | 17/6/2026 | The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Media (5.3) | 0.30% | — | Bootstrapped WP Recipe MakerAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brecht WP Recipe Maker wp-recipe-maker allows Code Injection.This issue affects WP Recipe Maker: from n/a through < 10.1.0. | |
| Aplazada | Media (6.4) | 0.23% | — | Epic Bootstrap ButtonsAI | 3/10/2025 | 17/6/2026 | The Epic Bootstrap Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icol’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (8.1) | 0.69% | — | Tiny Bootstrap Elements LightAI | 30/9/2025 | 17/6/2026 | The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code… | |
| Aplazada | Media (6.5) | 0.24% | — | Areoi ALL Bootstrap BlocksAI | 28/8/2025 | 25/9/2026 | Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All Bootstrap Blocks: from n/a through <= 1.3.28. | |
| Analizada | Media (5.4) | 0.31% | — | Mohsinrasool Twitter Bootstrap Collapse AKA Accordian Shortcode | 15/5/2025 | 17/6/2026 | The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting… | |
| Aplazada | Media (5.6) | 0.32% | — | Getbootstrap BootstrapAI | 15/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0. | |
| Analizada | Media (6.1) | 0.44% | — | Davidstutz Bootstrap Multiselect | 13/5/2025 | 17/6/2026 | An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through… | |
| Analizada | Media (6.1) | 0.24% | — | Bootstrap Site Alert Project Bootstrap Site Alert | 23/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap Site Alert allows Cross-Site Scripting (XSS).This issue affects Bootstrap Site Alert: from 0.0.0 before 1.13.0, from 3.0.0 before 3.0.4. | |
| Modificada | Media (4.8) | 0.58% | — | Oracle Graalvm FOR JDKOracle JDKOracle JRENetapp Bootstrap OS | 15/4/2025 | 17/6/2026 | Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6, 24; Oracle GraalVM for JDK: 21.0.6 and 24. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful… | |
| Aplazada | Alta (8.1) | 0.93% | — | G5theme Ultimate Bootstrap Elements FOR ElementorAI | 11/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Ultimate Bootstrap Elements for Elementor ultimate-bootstrap-elements-for-elementor allows PHP Local File Inclusion.This issue affects Ultimate Bootstrap Elements for Elementor: from n/a… | |
| Aplazada | Media (5.9) | 0.35% | — | Codetoolbox MY Bootstrap MenuAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetoolbox My Bootstrap Menu my-bootstrap-menu allows Stored XSS.This issue affects My Bootstrap Menu: from n/a through <= 1.2.1. | |
| Analizada | Media (4.4) | 0.39% | — | VIMNetapp Bootstrap OS | 13/3/2025 | 17/6/2026 | Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198. | |
| Aplazada | Media (6.4) | 0.24% | — | Bootstrapped WP Recipe MakerAI | 13/3/2025 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Roundup Recipe Name field in all versions up to, and including, 9.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Apache TomcatDebian LinuxNetapp Bootstrap OS | 10/3/2025 | 17/6/2026 | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1… | |
| Aplazada | Media (6.4) | 0.24% | — | Backdrop CMSAIBootstrap LiteAI | 7/3/2025 | 17/6/2026 | An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Backdrop CMS. It doesn't sufficiently sanitize certain class names. | |
| Aplazada | Media (6.4) | 0.24% | — | Backdrop CMSAIBootstrap 5 LiteAI | 7/3/2025 | 17/6/2026 | An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for Backdrop CMS. It doesn't sufficiently sanitize certain class names. |