Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.23% | — | Quantumcloud Simple Business Directory PROAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Reflected XSS.This issue affects Simple Business Directory Pro: from n/a through <= 15.5.1. | |
| Aplazada | Crítica (9.8) | 0.49% | — | Quantumcloud Simple Business Directory PROAI | 23/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9. | |
| Aplazada | Media (6.5) | 0.40% | — | Morgan KAY Chamber Dashboard Business DirectoryAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Morgan Kay Chamber Dashboard Business Directory allows DOM-Based XSS. This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.11. | |
| Aplazada | Media (5.3) | 0.27% | — | Businessdirectoryplugin Business Directory PluginAI | 13/3/2025 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.14 via the 'ajax_listing_submit_image_upload' function due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.57% | — | Connections-pro Connections Business DirectoryAI | 25/1/2025 | 17/6/2026 | The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all versions up to, and including, 10.4.66. This makes it possible for authenticated attackers, with Administrator-level access… | |
| Aplazada | Media (5.4) | 0.48% | — | Chandrika Guntur Chamber Dashboard Business DirectoryAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Chandrika Guntur, Morgan Kay Chamber Dashboard Business Directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.8. | |
| Aplazada | Media (6.4) | 0.34% | — | Chamber Dashboard Business DirectoryAI | 16/1/2025 | 17/6/2026 | The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'business_categories' shortcode in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (8) | 0.49% | — | Businessdirectoryplugin Business Directory | 18/6/2024 | 17/6/2026 | The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators, which can… | |
| Modificada | Media (5.4) | 0.31% | — | Businessdirectoryplugin Business Directory | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Businessdirectoryplugin Business Directory | 22/5/2024 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Modificada | Media (5.4) | 0.46% | — | Miniorange Staff / Employee Business Directory FOR Active Directory | 16/1/2024 | 17/6/2026 | The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against… | |
| Modificada | Alta (8.8) | 0.28% | — | Businessdirectoryplugin Business Directory | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Business Directory Team Business Directory Plugin – Easy Listing Directories for WordPress allows Cross-Site Request Forgery.This issue affects Business Directory Plugin – Easy Listing Directories for WordPress: from n/a through 6.3.10. | |
| Modificada | Media (4.9) | 0.91% | — | Miniorange Staff / Employee Business Directory FOR Active Directory | 27/9/2023 | 17/6/2026 | The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to… | |
| Modificada | Alta (7.5) | 0.67% | — | Phpjabbers Business Directory Script | 30/8/2023 | 17/6/2026 | phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter. | |
| Modificada | Media (6.1) | 0.43% | — | Phpjabbers Business Directory Script | 30/8/2023 | 17/6/2026 | phpjabbers Business Directory Script 3.2 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter. | |
| Modificada | Media (5.4) | 0.37% | — | Connections-pro Connections Business Directory | 26/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory plugin <= 10.4.36 versions. | |
| Modificada | Media (4.8) | 0.73% | — | Connections-pro Connections Business Directory | 1/11/2021 | 17/6/2026 | The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8) | 1.2% | — | Connections-pro Connections Business Directory | 1/11/2021 | 17/6/2026 | The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue | |
| Modificada | Media (4.3) | 0.47% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example) | |
| Modificada | Media (5.4) | 0.65% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin. | |
| Modificada | Media (6.5) | 0.71% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files, which could then be downloaded by the attacker to get access to PII, such as email, home addresses… | |
| Modificada | Alta (7.2) | 1.6% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE | |
| Modificada | Alta (8.8) | 0.67% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it could lead to RCE. | |
| Modificada | Alta (8.8) | 0.67% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues. | |
| Modificada | Media (6.1) | 1.0% | — | Chamber Dashboard Business Directory Project Chamber Dashboard Business Directory | 31/8/2020 | 17/6/2026 | The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS. |