Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.43% | — | Analytify - Google Analytics Dashboard | 2/5/2024 | 17/6/2026 | The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.43% | — | Monsterinsights Google Analytics BY Monster InsightsAI | 25/4/2024 | 17/6/2026 | Missing Authorization vulnerability in MonsterInsights Google Analytics by Monster Insights.This issue affects Google Analytics by Monster Insights: from n/a through 8.21.0. | |
| Modificada | Media (6.1) | 0.35% | — | Wpgoaltracker WP Google Analytics Events | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PineWise WP Google Analytics Events allows Reflected XSS.This issue affects WP Google Analytics Events: from n/a through 2.8.0. | |
| Aplazada | Media (5.4) | 0.46% | — | Sharethis Dashboard FOR Google AnalyticsAI | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in ShareThis ShareThis Dashboard for Google Analytics.This issue affects ShareThis Dashboard for Google Analytics: from n/a through 3.1.4. | |
| Modificada | Media (6.1) | 0.40% | — | Hasthemes HT Easy GA4 (google Analytics 4) | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) allows Stored XSS.This issue affects HT Easy GA4 ( Google Analytics 4 ): from n/a through 1.1.7. | |
| Modificada | Media (6.1) | 0.33% | — | Conversios Google Analytics Integration FOR Woocommerce | 26/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin <= 6.5.3 versions. | |
| Modificada | Alta (8.8) | 0.58% | — | Mainwp Google Analytics Extension | 12/10/2023 | 17/6/2026 | Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Multidots Enhanced Ecommerce Google Analytics FOR Woocommerce | 4/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Enhanced Ecommerce Google Analytics for WooCommerce plugin <= 3.7.1 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Hasthemes HT Easy GA4 (google Analytics 4) | 15/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions. | |
| Modificada | Media (5.4) | 0.37% | — | Monsterinsights Google Analytics Dashboard | 18/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions. | |
| Modificada | Media (6.1) | 0.58% | — | Google Analytics TOP Content Widget Project Google Analytics TOP Content Widget | 15/4/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Google Analytics Top Content Widget Plugin up to 1.5.6 on WordPress. Affected by this vulnerability is an unknown functionality of the file class-tgm-plugin-activation.php. The manipulation leads to cross site scripting. The attack can be launched remotely.… | |
| Modificada | Media (4.8) | 0.37% | — | Wp-buddy Google Analytics Opt-out | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP-Buddy Google Analytics Opt-Out plugin <= 2.3.4 versions. | |
| Modificada | Media (6.1) | 0.61% | — | Sterc Google Analytics Dashboard FOR Modx | 30/12/2022 | 17/6/2026 | A vulnerability was found in Sterc Google Analytics Dashboard for MODX up to 1.0.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file core/components/analyticsdashboardwidget/elements/tpl/widget.analytics.tpl of the component Internal Search. The manipulation… | |
| Modificada | Alta (8.8) | 0.33% | — | Analytify - Google Analytics Dashboard | 8/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress. | |
| Modificada | Media (6.1) | 0.65% | — | Yoast Google Analytics Dashboard | 24/6/2022 | 17/6/2026 | A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely. | |
| Modificada | Media (6.1) | 0.83% | — | Sharethis Dashboard FOR Google Analytics | 30/8/2021 | 17/6/2026 | The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be… | |
| Modificada | Media (5.4) | 0.74% | — | Lara's Google Analytics Project Lara's Google Analytics | 31/8/2020 | 17/6/2026 | lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS. | |
| Modificada | Media (6.1) | 1.4% | — | Bestwebsoft Google Analytics | 21/8/2019 | 17/6/2026 | The bws-google-analytics plugin before 1.7.1 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Media (4.3) | 2.0% | — | Yoast Google Analytics | 2/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manual_ua_code_field) field in the General Settings. |