Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.43%—Analytify - Google Analytics Dashboard2/5/202417/6/2026
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated…
AplazadaMedia (4.3)0.43%—Monsterinsights Google Analytics BY Monster InsightsAI25/4/202417/6/2026
Missing Authorization vulnerability in MonsterInsights Google Analytics by Monster Insights.This issue affects Google Analytics by Monster Insights: from n/a through 8.21.0.
ModificadaMedia (6.1)0.35%—Wpgoaltracker WP Google Analytics Events15/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PineWise WP Google Analytics Events allows Reflected XSS.This issue affects WP Google Analytics Events: from n/a through 2.8.0.
AplazadaMedia (5.4)0.46%—Sharethis Dashboard FOR Google AnalyticsAI25/3/202417/6/2026
Missing Authorization vulnerability in ShareThis ShareThis Dashboard for Google Analytics.This issue affects ShareThis Dashboard for Google Analytics: from n/a through 3.1.4.
ModificadaMedia (6.1)0.40%—Hasthemes HT Easy GA4 (google Analytics 4)19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) allows Stored XSS.This issue affects HT Easy GA4 ( Google Analytics 4 ): from n/a through 1.1.7.
ModificadaMedia (6.1)0.33%—Conversios Google Analytics Integration FOR Woocommerce26/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin <= 6.5.3 versions.
ModificadaAlta (8.8)0.58%—Mainwp Google Analytics Extension12/10/202317/6/2026
Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions.
ModificadaAlta (8.8)0.25%—Multidots Enhanced Ecommerce Google Analytics FOR Woocommerce4/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Enhanced Ecommerce Google Analytics for WooCommerce plugin <= 3.7.1 versions.
ModificadaAlta (8.8)0.27%—Hasthemes HT Easy GA4 (google Analytics 4)15/6/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions.
ModificadaMedia (5.4)0.37%—Monsterinsights Google Analytics Dashboard18/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions.
ModificadaMedia (6.1)0.58%—Google Analytics TOP Content Widget Project Google Analytics TOP Content Widget15/4/202317/6/2026
A vulnerability classified as problematic was found in Google Analytics Top Content Widget Plugin up to 1.5.6 on WordPress. Affected by this vulnerability is an unknown functionality of the file class-tgm-plugin-activation.php. The manipulation leads to cross site scripting. The attack can be launched remotely.…
ModificadaMedia (4.8)0.37%—Wp-buddy Google Analytics Opt-out7/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP-Buddy Google Analytics Opt-Out plugin <= 2.3.4 versions.
ModificadaMedia (6.1)0.61%—Sterc Google Analytics Dashboard FOR Modx30/12/202217/6/2026
A vulnerability was found in Sterc Google Analytics Dashboard for MODX up to 1.0.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file core/components/analyticsdashboardwidget/elements/tpl/widget.analytics.tpl of the component Internal Search. The manipulation…
ModificadaAlta (8.8)0.33%—Analytify - Google Analytics Dashboard8/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress.
ModificadaMedia (6.1)0.65%—Yoast Google Analytics Dashboard24/6/202217/6/2026
A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.
ModificadaMedia (6.1)0.83%—Sharethis Dashboard FOR Google Analytics30/8/202117/6/2026
The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be…
ModificadaMedia (5.4)0.74%—Lara's Google Analytics Project Lara's Google Analytics31/8/202017/6/2026
lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS.
ModificadaMedia (6.1)1.4%—Bestwebsoft Google Analytics21/8/201917/6/2026
The bws-google-analytics plugin before 1.7.1 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaMedia (4.3)2.0%—Yoast Google Analytics2/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manual_ua_code_field) field in the General Settings.