Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.30% | — | Comment Spam WiperAI | 21/3/2026 | 17/6/2026 | The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting in all versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and… | |
| Aplazada | Media (6.1) | 0.27% | — | Comment GeniusAI | 21/3/2026 | 17/6/2026 | The Comment Genius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (4.4) | 0.25% | — | Private CommentAI | 18/2/2026 | 17/6/2026 | The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in all versions up to, and including, 0.0.4. This is due to insufficient input sanitization and output escaping on the plugin's label text option. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.1) | 0.33% | — | Anycomment.io | 15/1/2026 | 17/6/2026 | Cross Site Scripting vulnerability in Anycomment anycomment.io 0.4.4 allows a remote attacker to execute arbitrary code via the Anycomment comment section | |
| Aplazada | Media (4.3) | 0.12% | — | Stopwords FOR CommentsAI | 14/1/2026 | 17/6/2026 | The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing nonce validation on the 'set_stopwords_for_comments' and 'delete_stopwords_for_comments' functions. This makes it possible for unauthenticated attackers to add… | |
| Aplazada | Media (4.3) | 0.19% | — | Quote CommentsAI | 7/1/2026 | 17/6/2026 | The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.0. This is due to missing authorization checks in the quotecomments_add_admin function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update… | |
| Aplazada | Media (5.3) | 0.26% | — | CommentsAI | 1/1/2026 | 17/6/2026 | The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet. | |
| Aplazada | Media (4.3) | 0.29% | — | Bologer AnycommentAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in Alexander AnyComment anycomment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyComment: from n/a through <= 0.3.6. | |
| Aplazada | Media (6.1) | 0.25% | — | Ping Comment SecretAI | 12/12/2025 | 17/6/2026 | The 评论小秘书 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.3.2. This is due to insufficient input sanitization and output escaping on the `$_SERVER['PHP_SELF']` variable in the plugin's settings page. This makes it… | |
| Aplazada | Media (5.3) | 0.29% | — | Comment Edit CoreAI | 13/11/2025 | 17/6/2026 | The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.0 via the 'ajax_get_comment' function. This makes it possible for unauthenticated attackers to extract sensitive data including user IDs, IP addresses, and email… | |
| Aplazada | Alta (7.5) | 0.43% | — | Bologer AnycommentAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alexander AnyComment anycomment allows PHP Local File Inclusion.This issue affects AnyComment: from n/a through <= 0.3.6. | |
| Aplazada | Alta (8.5) | 0.42% | — | Bologer AnycommentAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComment anycomment allows SQL Injection.This issue affects AnyComment: from n/a through <= 0.3.6. | |
| Aplazada | Media (4.3) | 0.16% | — | Widgetpack Comment SystemAI | 11/10/2025 | 17/6/2026 | The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.1. This is due to missing or incorrect nonce validation on the wpcmt_sync action in the wpcmt_request_handler function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.15% | — | Comment Info DetectorAI | 3/10/2025 | 17/6/2026 | The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing nonce validation on the options.php file when handling form submissions. This makes it possible for unauthenticated attackers to modify plugin settings via a… | |
| Aplazada | Media (5.9) | 0.18% | — | Alex Moss Google-plus-commentsAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Moss Google+ Comments google-plus-comments allows Stored XSS.This issue affects Google+ Comments: from n/a through <= 1.0. | |
| Aplazada | Media (5.9) | 0.22% | — | Habibur Rahman Comment Form WPAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Habibur Rahman Comment Form WP – Customize Default Comment Form comment-form-wp allows Stored XSS.This issue affects Comment Form WP – Customize Default Comment Form: from n/a through <= 2.0.1. | |
| Aplazada | Media (5.9) | 0.22% | — | Imaprogrammer Custom CommentAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imaprogrammer Custom Comment customcomment allows Stored XSS.This issue affects Custom Comment: from n/a through <= 2.1.6. | |
| Aplazada | Alta (7.1) | 0.24% | — | Digitalzoomstudio Comments Capcha BOXAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Comments Capcha Box comments-capcha-box allows Reflected XSS.This issue affects Comments Capcha Box: from n/a through <= 1.1. | |
| Aplazada | Media (6.4) | 0.25% | — | Surbma Recent Comments ShortcodeAI | 16/8/2025 | 17/6/2026 | The Surbma | Recent Comments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'recent-comments' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Crítica (9.4) | 0.41% | — | Joomla CommentboxAI | 28/7/2025 | 17/6/2026 | A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered. | |
| Aplazada | Alta (7) | 0.24% | — | Joomla CcommentAI | 23/7/2025 | 17/6/2026 | A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered. | |
| Analizada | Alta (7.2) | 2.1% | — | Markjaquith Subscribe TO Comments | 19/7/2025 | 17/6/2026 | The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the Path to header value. This allows authenticated attackers, with administrative privileges and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code… | |
| Aplazada | Media (5.4) | 0.19% | — | Anti Spam Spam Protection Block Spam Users Comments FormsAI | 6/6/2025 | 17/6/2026 | The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.7. This is due to missing or incorrect nonce validation in the 'ss_option_maint.php' and 'ss_user_filter_list' files. This makes it possible for… | |
| Aplazada | Alta (8.8) | 2.1% | 💥 Exploit | HypercommentsAI | 5/6/2025 | 17/6/2026 | The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hc_request_handler function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to update arbitrary… | |
| Aplazada | Media (6.4) | 0.29% | — | Wordpress Comments Import ExportAI | 2/6/2025 | 17/6/2026 | The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings function in all versions up to, and including, 2.4.3. Additionally, the plugin fails to properly sanitize and escape FTP settings parameters. This makes… |