Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.43% | — | Adtribes Product Feed PROAI | 15/8/2026 | 26/8/2026 | The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy. | |
| Aplazada | Baja (1.9) | 0.14% | — | Feedmob Fm-mcp-serversAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be… | |
| Aplazada | Media (5.5) | 0.31% | — | Feedzy RSS AggregatorAI | 10/8/2026 | 26/8/2026 | The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import job, reset its deduplication and… | |
| Aplazada | Crítica (9.1) | 0.82% | — | CTX FeedAI | 6/8/2026 | 12/8/2026 | Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Houzez Property FeedAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. | |
| Aplazada | Media (4.7) | 0.39% | — | Smashballoon Social Photo FeedAI | 5/8/2026 | 12/8/2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query String in all versions up to, and including, 6.11.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (8.1) | 0.39% | — | Product Feed Manager FOR WoocommerceAI | 31/7/2026 | 26/8/2026 | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks. | |
| Aplazada | Alta (7.5) | 0.41% | — | Wp-feedstats Wordpress PluginAI | 31/7/2026 | 26/8/2026 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes. | |
| Aplazada | Media (4.9) | 0.19% | — | FeedzyAI | 27/7/2026 | 27/7/2026 | Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Product Feed ManagerAI | 27/7/2026 | 27/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Wp-feedstats Wordpress PluginAI | 22/7/2026 | 22/7/2026 | The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment. | |
| Aplazada | Alta (8.7) | 0.51% | — | FeedbinAI | 21/7/2026 | 23/7/2026 | Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely. Attackers can iterate sequential integer… | |
| Aplazada | Media (5.4) | 0.14% | — | Wp-feedstats Wordpress PluginAI | 20/7/2026 | 20/7/2026 | The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's… | |
| Aplazada | Media (4.8) | 0.13% | — | Smashballoon Reviews FeedAI | 20/7/2026 | 21/7/2026 | The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the… | |
| Aplazada | Media (6.1) | 0.38% | — | Webappick Product Feed Manager FOR WoocommerceAI | 16/7/2026 | 16/7/2026 | The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Analizada | Baja (3.1) | 0.21% | — | Anuaralfetahe Advanced Content Feedback | 10/7/2026 | 6/8/2026 | Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0. | |
| Analizada | Media (6.1) | 0.25% | — | Anuaralfetahe Advanced Content Feedback | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Stored XSS. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0. | |
| Aplazada | Media (4.7) | 0.15% | — | Smashballoon Social Photo FeedAI | 8/7/2026 | 8/7/2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.1) | 0.25% | — | Etruel Wpematico RSS Feed FetcherAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions. | |
| Aplazada | Media (6.4) | 0.35% | — | FeedzyAI | 2/7/2026 | 2/7/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'aspectRatio' Attribute in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (4.9) | 0.48% | — | Wp-property-hive Houzez Property FeedAI | 2/7/2026 | 2/7/2026 | The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the prepare_items() method of the… | |
| Aplazada | Alta (8.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 23/6/2026 | 23/6/2026 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above. | |
| Aplazada | Alta (7.1) | 0.25% | — | Social Slider FeedAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Feed KuantokustaAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | CTX FeedAIPHPAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions. |