Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.36% | — | Radiustheme Classified Listing | 25/2/2025 | 17/6/2026 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.4 via the rtcl_taxonomy_settings_export function. This makes it possible for unauthenticated attackers to extract sensitive data including… | |
| Modificada | Alta (8.8) | 0.26% | — | Webcodingplace Ultimate Classified Listings | 20/2/2025 | 17/6/2026 | The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the update_profile function. This makes it possible for unauthenticated attackers to modify victim's email via a forged… | |
| Analizada | Media (4.8) | 0.23% | — | Webcodingplace Ultimate Classified Listings | 20/2/2025 | 17/6/2026 | The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject… | |
| Aplazada | Media (6.5) | 0.31% | — | Webcodingplace Ultimate Classified ListingsAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Ultimate Classified Listings ultimate-classified-listings allows Stored XSS.This issue affects Ultimate Classified Listings: from n/a through <= 1.7. | |
| Aplazada | Alta (7.5) | 0.57% | — | Webcodingplace Ultimate Classified ListingsAI | 20/11/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate Classified Listings ultimate-classified-listings allows PHP Local File Inclusion.This issue affects Ultimate Classified Listings: from n/a through <= 1.7. | |
| Aplazada | Alta (8.8) | 0.56% | — | Radiustheme Classified ListingAI | 19/11/2024 | 17/6/2026 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigured check on the 'rtcl_import_settings' function in all versions up to, and including, 3.1.15.1. This makes it possible… | |
| Aplazada | Media (5.3) | 0.47% | — | Radiustheme Classified ListingAI | 16/11/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This issue affects Classified Listing: from n/a through <= 3.1.16. | |
| Analizada | Media (4.3) | 0.29% | — | Radiustheme Classified Listing | 13/9/2024 | 17/6/2026 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(), update_fb_options(), and many more in all versions up to, and including, 3.1.7. This makes it… | |
| Analizada | Alta (7.1) | 0.96% | 💥 PoC | Webcodingplace Ultimate Classified Listings | 1/8/2024 | 17/6/2026 | The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Media (4.7) | 0.38% | — | Webcodingplace Ultimate Classified Listings | 29/7/2024 | 17/6/2026 | The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Alta (7.5) | 0.76% | — | Webcodingplace Ultimate Classified Listings | 29/7/2024 | 17/6/2026 | The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page | |
| Modificada | Media (4.3) | 0.36% | — | Radiustheme Classified Listing | 25/4/2024 | 17/6/2026 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the rtcl_fb_gallery_image_delete AJAX action in all versions up to, and including, 3.0.10.3. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.3) | 0.55% | — | Radiustheme Classified Listing | 9/4/2024 | 17/6/2026 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on the rtcl_import_location() rtcl_import_category() functions in all versions up to, and including, 3.0.4. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.45% | — | Radiustheme Classified Listing | 9/4/2024 | 17/6/2026 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing or incorrect nonce validation on the 'rtcl_update_user_account' function. This makes it possible for unauthenticated… | |
| Modificada | Alta (8.8) | 0.25% | — | Radiustheme Classified Listing | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions. | |
| Modificada | Media (6.1) | 0.70% | — | Radiustheme Classified Listing | 16/9/2022 | 17/6/2026 | The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.62% | — | Radiustheme Classified ListingRadiustheme Classified Listing Store & MembershipRadiustheme ClassimaRadiustheme Classima Core | 16/9/2022 | 17/6/2026 | The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected… | |
| Modificada | Media (4.3) | 0.93% | — | Preprojects PRE Classified Listings ASP | 13/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to inject arbitrary web script or HTML via the address parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Preprojects PRE Classified Listings ASP | 13/4/2010 | 16/6/2026 | SQL injection vulnerability in detailad.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the siteid parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects PRE Classified Listings ASP | 13/4/2010 | 16/6/2026 | SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Preprojects PRE Classified Listings | 3/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject arbitrary web script or HTML via the address parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Preprojects PRE Classified Listings | 3/8/2009 | 16/6/2026 | SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the siteid parameter. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Preprojects PRE Classified Listings | 20/2/2009 | 16/6/2026 | Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin". | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Dmxready Classified Listings Manager | 5/2/2009 | 16/6/2026 | SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Media (5) | 1.1% | — | Preprojects PRE Classified Listings | 4/2/2009 | 16/6/2026 | PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request. |