Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.36% | — | Fivestarplugins Five Star Restaurant Menu | 5/6/2024 | 17/6/2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.35% | — | Highfivery LLC Zero SpamAI | 17/5/2024 | 17/6/2026 | Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6. | |
| Aplazada | Media (5.3) | 0.38% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16. | |
| Aplazada | Media (6.5) | 0.32% | — | Fivestarplugins Five Star Restaurant MenuAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Menu allows Stored XSS.This issue affects Five Star Restaurant Menu: from n/a through 2.4.14. | |
| Modificada | Media (5.4) | 0.31% | — | Fivestarplugins Five Star Restaurant Menu | 5/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five Star Restaurant Reviews: from n/a through 2.3.5. | |
| Modificada | Crítica (9.8) | 1.2% | — | Fivestarplugins Five Star Restaurant Menu | 20/11/2023 | 17/6/2026 | The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog. | |
| Modificada | Alta (7.2) | 0.73% | — | Highfivery Zero Spam FOR Wordpress | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Highfivery LLC Zero Spam for WordPress allows SQL Injection.This issue affects Zero Spam for WordPress: from n/a through 5.4.4. | |
| Modificada | Media (6.1) | 0.41% | — | Fivestarplugins Five Star Restaurant Menu | 25/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Fivestarplugins Five Star Restaurant Menu | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions. | |
| Modificada | Crítica (9.8) | 0.67% | — | Aista Phosphorus Five | 7/1/2023 | 17/6/2026 | A vulnerability has been found in polterguy Phosphorus Five up to 8.2 and classified as critical. This vulnerability affects the function csv.Read of the file plugins/extras/p5.mysql/NonQuery.cs of the component CSV Import. The manipulation leads to sql injection. Upgrading to version 8.3 is able to address this… | |
| Modificada | Media (6.1) | 0.55% | — | Fivestarplugins Five Star Restaurant Reservations | 21/11/2022 | 17/6/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could… | |
| Modificada | Baja (2.7) | 0.80% | — | Five Minute Webshop Project Five Minute Webshop | 8/6/2022 | 17/6/2026 | The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection | |
| Modificada | Media (4.9) | 0.99% | — | Five Minute Webshop Project Five Minute Webshop | 8/6/2022 | 17/6/2026 | The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection | |
| Modificada | Crítica (9.8) | 2.0% | — | Highfivery Zero-spam | 14/3/2022 | 17/6/2026 | The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection | |
| Modificada | Media (5.4) | 0.60% | — | Fivestarplugins Five Star Business Profile AND Schema | 21/2/2022 | 17/6/2026 | The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of… | |
| Modificada | Media (5.4) | 0.61% | — | Fivestarplugins Five Star Restaurant Reservations | 24/1/2022 | 17/6/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting… | |
| Modificada | Crítica (9.8) | 31% | — | Fivestarplugins Five Star Restaurant Menu | 11/3/2021 | 17/6/2026 | The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php. | |
| Modificada | Alta (7.5) | 1.3% | — | 2pisoftware Cmfive | 1/6/2020 | 17/6/2026 | system/classes/DbPDO.php in Cmfive through 2015-03-15, when database connectivity malfunctions, allows remote attackers to obtain sensitive information (username and password) via any request, such as a password reset request. | |
| Modificada | Alta (7.5) | 1.8% | — | Five9 Agent Desktop Plus | 21/3/2019 | 17/6/2026 | Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service via opening a connection on port 8083 to a device running the Five9 SoftPhone(issue 1 of 2). | |
| Modificada | Crítica (9.8) | 1.6% | — | Five9 Agent Desktop Plus | 18/3/2019 | 17/6/2026 | Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2). | |
| Modificada | Crítica (9.8) | 2.8% | — | Nexusfi Opac Easyweb Five | 3/10/2018 | 17/6/2026 | An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter. | |
| Modificada | Media (6.8) | 1.1% | — | Fiverrscript | 19/6/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in FiverrScript (aka Fiverr Script) 7.2 allows remote attackers to hijack the authentication of administrators for requests that create a new admin via a request to administrator/admins_create.php. | |
| Modificada | Media (5) | 1.8% | — | Lullabot Fivestar Module FOR Drupal | 14/8/2012 | 16/6/2026 | The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter. | |
| Modificada | Media (6.8) | 0.72% | — | Lullabot Fivestar Module FOR Drupal | 22/7/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requests that cast votes. | |
| Modificada | Alta (7.5) | 1.0% | — | Fivedollarscripts Drinks | 20/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Five Dollar Scripts Drinks script allows remote attackers to execute arbitrary SQL commands via the recid parameter. |