Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
378 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.43% | — | BigbluebuttonAI | 18/5/2026 | 24/7/2026 | BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicious actor to craft and carry out a targeted XSS attack, activated on anyone replaying the recording. This issue has been… | |
| Aplazada | Media (6.5) | 0.30% | — | BigbluebuttonAI | 22/4/2026 | 17/6/2026 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available. | |
| Aplazada | Media (4.3) | 0.28% | — | BigbluebuttonAI | 22/4/2026 | 17/6/2026 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that the default logoutURL is used. No known workarounds are available. | |
| Aplazada | Alta (7.5) | 0.16% | — | Analytify Simple Social Media Share ButtonsAI | 7/4/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects Simple Social Media Share Buttons: from n/a through 6.2.0. | |
| Aplazada | Media (6.4) | 0.33% | — | WP Random ButtonAI | 21/3/2026 | 17/6/2026 | The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text' shortcode attributes of the 'wp_random_button' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode… | |
| Aplazada | Media (4.3) | 0.13% | — | Purchase Button FOR Affiliate LinkAI | 7/3/2026 | 17/6/2026 | The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing nonce validation on the settings page form handler in `inc/purchase-btn-options-page.php`. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (6.1) | 0.26% | — | Bigbluebutton | 25/2/2026 | 17/6/2026 | BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads to an Open Redirect vulnerability. BigBlueButton 3.0.20 patches the issue. No known workarounds are… | |
| Analizada | Baja (2.4) | 0.28% | — | Bigbluebutton | 21/2/2026 | 17/6/2026 | BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the microphone muted, the client sends audio to the server regardless of mute state. Media is discarded at the server side, so it isn't audible to any participants, but this may allow for malicious server… | |
| Analizada | Alta (8.2) | 0.58% | — | Bigbluebutton | 21/2/2026 | 17/6/2026 | BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains instructions that leave a BBB server vulnerable for Denial of Service. The flawed command exposes both ports (3310 and 7357)… | |
| Aplazada | Media (4.3) | 0.15% | — | Bitcoin Donate ButtonAI | 28/1/2026 | 17/6/2026 | The Bitcoin Donate Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the settings page. This makes it possible for unauthenticated attackers to modify the plugin's settings, including donation… | |
| Aplazada | Media (5.3) | 0.36% | — | Paypalcheckout Payment Button FOR PaypalAI | 17/1/2026 | 17/6/2026 | The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 1.2.3.41. This is due to the plugin exposing a public AJAX endpoint (`wppaypalcheckout_ajax_process_order`) that processes checkout results without any authentication or server-side… | |
| Aplazada | Media (4.3) | 0.16% | — | Sosh Share ButtonsAI | 14/1/2026 | 17/6/2026 | The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the 'admin_page_content' function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request… | |
| Aplazada | Alta (8.8) | 0.29% | — | Social-share-buttonsAI | 13/1/2026 | 17/6/2026 | Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted POST requests with malicious SQL payloads to retrieve and potentially steal entire database contents. | |
| Aplazada | Media (4.3) | 0.14% | — | Sticky Action ButtonsAI | 7/1/2026 | 17/6/2026 | The Sticky Action Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the sabs_options_page_form_submit() function. This makes it possible for unauthenticated attackers to update plugin settings via… | |
| Aplazada | Media (6.4) | 0.22% | — | Viitor Button ShortcodesAI | 7/1/2026 | 17/6/2026 | The Viitor Button Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' shortcode attribute in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (5.4) | 0.16% | — | Merkulove Buttoner FOR ElementorAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in merkulove Buttoner for Elementor buttoner-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Buttoner for Elementor: from n/a through <= 1.0.6. | |
| Aplazada | Media (6.4) | 0.22% | — | Css3 ButtonsAI | 6/12/2025 | 17/6/2026 | The CSS3 Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.23% | — | Ultra Skype ButtonAI | 6/12/2025 | 17/6/2026 | The Ultra Skype Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_id' parameter of the [ultra_skype] shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.23% | — | Save AS PDF ButtonAI | 13/11/2025 | 30/9/2026 | The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbutton shortcode in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.17% | — | Idiom Easy Social Share ButtonsAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Easy Social Share Buttons easy-social-share-buttons3 allows Reflected XSS.This issue affects Easy Social Share Buttons: from n/a through < 10.7.1. | |
| Aplazada | Media (5.3) | 0.33% | — | Melabuwp Download Counter ButtonAI | 5/11/2025 | 17/6/2026 | The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files. | |
| Aplazada | Media (4.3) | 0.27% | — | Callnowbutton Call NOW ButtonAI | 29/10/2025 | 17/6/2026 | The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (4.3) | 0.23% | — | Callnowbutton Call NOW ButtonAI | 29/10/2025 | 17/6/2026 | The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (5.9) | 0.22% | — | Nikitas Georgopoulos Weshare ButtonsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NIKITAS GEORGOPOULOS WeShare Buttons e-mailit allows Stored XSS.This issue affects WeShare Buttons: from n/a through <= 13.0.0. | |
| Aplazada | Media (6.4) | 0.23% | — | Print Button ShortcodeAI | 22/10/2025 | 17/6/2026 | The Print Button Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'print-button' shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping on the 'target' attribute. This makes it possible for authenticated attackers,… |