Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.64%—Export User Project Export User14/4/202317/6/2026
The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
ModificadaAlta (8)1.1%—Codection Import AND Export Users AND Customers7/11/202217/6/2026
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
ModificadaMedia (4.8)0.71%—Codection Import AND Export Users AND Customers2/5/202217/6/2026
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues
ModificadaAlta (7.2)1.4%—Export Users With Meta Project Export Users With Meta6/7/202117/6/2026
The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to an authenticated SQL Injection.
ModificadaAlta (8)1.8%—Codection Import AND Export Users AND Customers4/11/202017/6/2026
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
ModificadaMedia (6.1)1.3%—Export Users TO CSV Project Export Users TO CSV28/2/202017/6/2026
The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection.
ModificadaAlta (8.6)1.5%—Export Users TO CSV Project Export Users TO CSV28/8/201817/6/2026
The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection.
Orbitaley — Vulnerabilidades