Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.59%—Silbersaiten Order Duplicator7/11/202317/6/2026
In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can download personal information from ps_customer/ps_address tables…
ModificadaAlta (8.8)0.73%—Wpspeedx Rduplicator31/8/202317/6/2026
The Quick Post Duplicator for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with…
ModificadaMedia (6.1)0.38%—Awesomemotive Duplicator28/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.
ModificadaMedia (4.8)0.46%—Duplicator EZP Maintenance Mode15/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Maintenance Mode plugin <= 1.0.1 versions.
ModificadaMedia (6.1)0.63%—Metaphorcreations Post Duplicator20/2/202317/6/2026
A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function mtphr_post_duplicator_notice of the file includes/notices.php. The manipulation of the argument post-duplicated leads to cross site scripting. It is possible to launch…
ModificadaMedia (5.3)11%💥 ExploitAwesomemotive Duplicator22/8/202217/6/2026
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
ModificadaAlta (7.5)17%💥 ExploitAwesomemotive Duplicator22/8/202217/6/2026
The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.
ModificadaMedia (5.4)0.64%—Metaphorcreations Post Duplicator10/3/202217/6/2026
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application root…
AnalizadaAlta (7.5)98%⚠ Explotación activa💥 ExploitAwesomemotive Duplicator13/4/202017/6/2026
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
ModificadaAlta (8.8)0.73%—Wpmaz Multisite Post Duplicator13/9/201917/6/2026
The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
ModificadaCrítica (9.8)60%💥 ExploitAwesomemotive Duplicator19/9/201817/6/2026
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
ModificadaMedia (6.1)3.3%💥 ExploitAwesomemotive Duplicator26/3/201817/6/2026
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.
ModificadaMedia (6.1)1.0%—Snapcreek Duplicator14/11/201717/6/2026
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly.
ModificadaAlta (8.2)7.5%💥 ExploitSnapcreek Duplicator7/8/201717/6/2026
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
ModificadaMedia (4.3)11%💥 ExploitCory Lamle Duplicator9/8/201316/6/2026
Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.
Orbitaley — Vulnerabilidades