Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.59% | — | Silbersaiten Order Duplicator | 7/11/2023 | 17/6/2026 | In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can download personal information from ps_customer/ps_address tables… | |
| Modificada | Alta (8.8) | 0.73% | — | Wpspeedx Rduplicator | 31/8/2023 | 17/6/2026 | The Quick Post Duplicator for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with… | |
| Modificada | Media (6.1) | 0.38% | — | Awesomemotive Duplicator | 28/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions. | |
| Modificada | Media (4.8) | 0.46% | — | Duplicator EZP Maintenance Mode | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Maintenance Mode plugin <= 1.0.1 versions. | |
| Modificada | Media (6.1) | 0.63% | — | Metaphorcreations Post Duplicator | 20/2/2023 | 17/6/2026 | A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function mtphr_post_duplicator_notice of the file includes/notices.php. The manipulation of the argument post-duplicated leads to cross site scripting. It is possible to launch… | |
| Modificada | Media (5.3) | 11% | 💥 Exploit | Awesomemotive Duplicator | 22/8/2022 | 17/6/2026 | The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site. | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Awesomemotive Duplicator | 22/8/2022 | 17/6/2026 | The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating. | |
| Modificada | Media (5.4) | 0.64% | — | Metaphorcreations Post Duplicator | 10/3/2022 | 17/6/2026 | A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application root… | |
| Analizada | Alta (7.5) | 98% | ⚠ Explotación activa💥 Exploit | Awesomemotive Duplicator | 13/4/2020 | 17/6/2026 | The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init. | |
| Modificada | Alta (8.8) | 0.73% | — | Wpmaz Multisite Post Duplicator | 13/9/2019 | 17/6/2026 | The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF. | |
| Modificada | Crítica (9.8) | 60% | 💥 Exploit | Awesomemotive Duplicator | 19/9/2018 | 17/6/2026 | An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution. | |
| Modificada | Media (6.1) | 3.3% | 💥 Exploit | Awesomemotive Duplicator | 26/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter. | |
| Modificada | Media (6.1) | 1.0% | — | Snapcreek Duplicator | 14/11/2017 | 17/6/2026 | installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly. | |
| Modificada | Alta (8.2) | 7.5% | 💥 Exploit | Snapcreek Duplicator | 7/8/2017 | 17/6/2026 | The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files. | |
| Modificada | Media (4.3) | 11% | 💥 Exploit | Cory Lamle Duplicator | 9/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter. |