Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.29% | — | Olivethemes Olive ONE Click Demo Import | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. | |
| Modificada | Alta (7.2) | 0.50% | — | Ocdi ONE Click Demo Import | 14/5/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0. | |
| Aplazada | Media (4.3) | 0.18% | — | Famethemes Fametheme Demo ImporterAI | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FameThemes FameTheme Demo Importer.This issue affects FameTheme Demo Importer: from n/a through 1.1.5. | |
| Modificada | Crítica (9.8) | 0.58% | — | Olivethemes Olive ONE Click Demo Import | 20/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. | |
| Modificada | Alta (7.2) | 1.2% | — | Themely Theme Demo Import | 16/1/2024 | 17/6/2026 | Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed. | |
| Modificada | Alta (7.2) | 0.80% | — | Olivethemes Olive ONE Click Demo Import | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. | |
| Modificada | Alta (7.2) | 0.80% | — | Themely Theme Demo Import | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Themely Theme Demo Import.This issue affects Theme Demo Import: from n/a through 1.1.1. | |
| Modificada | Alta (7.2) | 1.1% | — | Postmagthemes Demo Import | 5/12/2022 | 17/6/2026 | The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE. | |
| Modificada | Alta (8.8) | 0.58% | — | Rarathemes Rara ONE Click Demo Import | 29/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory. | |
| Modificada | Alta (8.1) | 0.48% | — | Accesspressthemes Access Demo Importer | 18/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media). | |
| Modificada | Media (6.5) | 0.49% | — | Accesspressthemes Access Demo Importer | 18/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin. | |
| Modificada | Alta (7.2) | 1.7% | — | Ocdi ONE Click Demo Import | 11/4/2022 | 17/6/2026 | The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed | |
| Modificada | Alta (7.2) | 1.4% | — | Catchplugins Catch Themes Demo Import | 7/3/2022 | 17/6/2026 | The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set… | |
| Modificada | Alta (8.1) | 1.1% | — | Hashthemes Demo Importer | 1/11/2021 | 17/6/2026 | The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads. | |
| Modificada | Alta (7.2) | 56% | 💥 Exploit | Catchplugins Catch Themes Demo Import | 21/10/2021 | 17/6/2026 | The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to… | |
| Modificada | Media (5.7) | 0.42% | — | Catchplugins Catch Scroll Progress BARCatchplugins Catch Sticky MenuCatchplugins Catch Themes Demo ImportCatchplugins Catch Under Construction+6 | 18/10/2021 | 17/6/2026 | Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before… | |
| Modificada | Alta (8.8) | 1.7% | — | Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+39 | 11/10/2021 | 17/6/2026 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the… | |
| Modificada | Alta (8.8) | 0.65% | — | Themegrill Demo Importer | 5/5/2021 | 17/6/2026 | themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database. | |
| Modificada | Crítica (9.1) | 4.1% | 💥 Exploit | Themegrill Demo Importer | 5/5/2021 | 17/6/2026 | themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook. |