Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 1.3% | — | YMC FilterAI | 25/6/2026 | 26/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5. | |
| Aplazada | Media (6.4) | 0.33% | — | Avalon23 Products Filter FOR WoocommerceAI | 24/6/2026 | 25/6/2026 | The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and including, 1.1.6. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (notably 'title' and… | |
| Aplazada | Crítica (9.3) | 0.40% | — | JetsmartfiltersAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Woocommerce Product FiltersAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Product Filter Widget FOR ElementorAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor <= 1.0.6 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | WBW Product FilterAI | 11/6/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter by WBW: from n/a through 3.1.2. | |
| Aplazada | Media (5.4) | 0.23% | — | Berocket Advanced Ajax Product FiltersAI | 11/6/2026 | 29/9/2026 | Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced AJAX Product Filters: from n/a through 1.6.3.3. | |
| Aplazada | Media (6.1) | 0.21% | — | Product Filter Widget FOR ElementorAI | 9/6/2026 | 23/7/2026 | The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.3) | 0.15% | — | Kddi Corporation Anshin Filter FOR AUAI | 14/5/2026 | 17/6/2026 | Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify communications transmitted in plaintext, potentially resulting in information disclosure or data tampering. | |
| Aplazada | Media (4.8) | 0.26% | — | Woof Products Filter FOR WoocommerceAI | 13/5/2026 | 17/6/2026 | WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering XSS payloads in design tab textfields. Attackers can inject JavaScript code through fields like 'Text for block toggle' and 'Custom front css… | |
| Pendiente de análisis | Baja (2.1) | 0.32% | — | Wikimedia AbusefilterAI | 11/5/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation AbuseFilter. This issue affects AbuseFilter: from * before 1.43.7, 1.44.4, 1.45.2. | |
| Aplazada | Media (5.1) | 0.19% | — | Filterable Portfolio GalleryAI | 10/5/2026 | 25/7/2026 | Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is previewed,… | |
| Aplazada | Media (4.3) | 0.20% | — | Fast AND Fancy FilterAI | 22/4/2026 | 17/6/2026 | The Fast & Fancy Filter – 3F plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce verification in the saveFields() function, which handles the fff_save_settins AJAX action. This makes it possible for unauthenticated attackers to modify… | |
| Aplazada | Media (4.3) | 0.20% | — | McatfilterAI | 22/4/2026 | 17/6/2026 | The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settings updates. The compute_post() function is called in the… | |
| Aplazada | Media (4.4) | 0.39% | — | Short Comment FilterAI | 22/4/2026 | 17/6/2026 | The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Minimum Count' settings field in all versions up to and including 2.2. This is due to insufficient input sanitization (no sanitize callback on register_setting) and missing output escaping (no esc_attr() on the echoed… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Financial Services Transaction Filtering | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Transaction Filtering product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.1.2.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (8.6) | 0.45% | — | WBW Product Filter FOR WoocommerceAI | 13/4/2026 | 17/6/2026 | The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks | |
| Aplazada | Alta (7.5) | 1.7% | — | Wcapf Woocommerce Ajax Product FilterAI | 8/4/2026 | 24/7/2026 | WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.23% | — | Wpbens Filter PlusAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Wpbens Filter Plus filter-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filter Plus: from n/a through <= 1.1.17. | |
| Aplazada | Media (6.5) | 0.22% | — | Awplife Blog FilterAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.6. | |
| Aplazada | Media (6.5) | 0.48% | — | WBW Product Filter FOR WoocommerceAI | 24/3/2026 | 17/6/2026 | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versions up to, and including, 3.1.2. This is due to the plugin's MVC framework dynamically registering unauthenticated AJAX handlers via `wp_ajax_nopriv_` hooks without… | |
| Aplazada | Media (5.3) | 0.26% | — | YMC Filter AND GridsAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in YMC Filter & Grids ymc-smart-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filter & Grids: from n/a through <= 3.5.1. | |
| Aplazada | Media (6.8) | 0.16% | — | DAJ I-filterAI | 10/3/2026 | 17/6/2026 | Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system directory or backup directory by a non-administrative user. | |
| Aplazada | Alta (7.2) | 0.43% | — | Xforwoocommerce Product Filter FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in XforWooCommerce Product Filter for WooCommerce prdctfltr allows Privilege Escalation.This issue affects Product Filter for WooCommerce: from n/a through <= 9.1.2. | |
| Aplazada | Alta (7.1) | 0.24% | — | BAS Schuiling Feedwordpress Advanced FiltersAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bas Schuiling FeedWordPress Advanced Filters faf allows Reflected XSS.This issue affects FeedWordPress Advanced Filters: from n/a through <= 0.6.2. |