Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.27% | — | Sumitsurai Featured Posts With Multiple Custom GroupsAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sumitsurai Featured Posts with Multiple Custom Groups (FPMCG) featured-posts-with-multiple-custom-groups-fpmcg allows Reflected XSS.This issue affects Featured Posts with Multiple Custom Groups (FPMCG): from n/a… | |
| Aplazada | Media (6.5) | 0.21% | — | Sumitsurai Featured Posts With Multiple Custom GroupsAI | 17/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sumitsurai Featured Posts with Multiple Custom Groups (FPMCG) featured-posts-with-multiple-custom-groups-fpmcg allows Cross Site Request Forgery.This issue affects Featured Posts with Multiple Custom Groups (FPMCG): from n/a through <= 4.0. | |
| Aplazada | Media (5.3) | 0.34% | — | TAG GroupsAI | 25/9/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Steve Burge WordPress Tag Cloud Plugin – Tag Groups tag-groups.This issue affects WordPress Tag Cloud Plugin – Tag Groups: from n/a through <= 2.0.3. | |
| Analizada | Baja (2.7) | 0.43% | — | Uncannyowl Uncanny Groups FOR Learndash | 25/9/2024 | 17/6/2026 | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated attackers, with group leader-level access and… | |
| Analizada | Alta (7.2) | 1.2% | — | Uncannyowl Uncanny Groups FOR Learndash | 25/9/2024 | 17/6/2026 | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above,… | |
| Modificada | Alta (8.2) | 0.49% | — | Davidcramer Plugin Groups | 21/2/2024 | 17/6/2026 | The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_init() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to change the settings of the plugin, which can also cause a denial… | |
| Modificada | Crítica (9.8) | 0.79% | — | Bbossgroups Bboss | 28/7/2023 | 17/6/2026 | bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument. | |
| Modificada | Media (6.8) | 1.0% | — | Groupsession | 24/12/2021 | 17/6/2026 | Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows an attacker with an administrative privilege to obtain sensitive information stored in the hierarchy above the directory on the published site's… | |
| Modificada | Media (6.1) | 0.82% | — | Groupsession | 24/12/2021 | 17/6/2026 | Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks by having a user to access a specially… | |
| Modificada | Alta (7.5) | 1.3% | — | Groupsession | 24/12/2021 | 17/6/2026 | Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the server and obtain sensitive information… | |
| Modificada | Media (6.1) | 0.87% | — | GroupsessionGroupsession BycloudGroupsession Zion | 30/7/2021 | 17/6/2026 | Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to redirect a user to an arbitrary… | |
| Modificada | Media (4.3) | 0.92% | — | GroupsessionGroupsession BycloudGroupsession Zion | 30/7/2021 | 17/6/2026 | Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote authenticated attacker… | |
| Modificada | Media (4.8) | 0.64% | — | GroupsessionGroupsession BycloudGroupsession Zion | 30/7/2021 | 17/6/2026 | Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to inject an arbitrary script… | |
| Modificada | Media (4.3) | 0.45% | — | GroupsessionGroupsession BycloudGroupsession Zion | 30/7/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to hijack the… | |
| Modificada | Media (4.8) | 0.60% | — | GroupsessionGroupsession BycloudGroupsession Zion | 30/7/2021 | 17/6/2026 | Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to inject an arbitrary script… | |
| Modificada | Media (6.1) | 0.78% | — | Uncannyowl Uncanny Groups FOR Learndash | 23/12/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remote attackers to inject arbitrary JavaScript or HTML via the ulgm_code_redeem POST Parameter in user-code-redemption.php, the ulgm_user_first POST Parameter in user-registration-form.php, the… | |
| Modificada | Media (4.3) | 1.2% | — | Organic Groups Project Organic Groups | 18/2/2020 | 16/6/2026 | The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary private groups via unspecified vectors. | |
| Modificada | Media (6.5) | 0.44% | — | JJJ WP User Groups | 26/6/2018 | 17/6/2026 | WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been fixed in 2.1.1. | |
| Modificada | Media (6.1) | 0.77% | — | Groupsession | 26/1/2018 | 17/6/2026 | Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (6.5) | 1.3% | — | Groupsession | 9/6/2017 | 17/6/2026 | GroupSession versions 4.6.4 and earlier allows remote authenticated attackers to bypass access restrictions to obtain sensitive information such as emails via unspecified vectors. | |
| Modificada | Crítica (9.8) | 4.7% | — | Redhat JgroupsRedhat Jboss Enterprise Application Platform | 30/6/2016 | 17/6/2026 | It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message… | |
| Modificada | Baja (3.5) | 0.95% | — | Drupal Organic Groups Menu | 12/11/2014 | 17/6/2026 | The Organic Groups Menu (aka OG Menu) module before 7.x-2.2 for Drupal allows remote authenticated users with the "access administration pages" permission to change module settings via unspecified vectors. | |
| Modificada | Media (5) | 1.9% | — | Groups Communities AND CO Project GCC | 27/5/2014 | 16/6/2026 | The Groups, Communities and Co (GCC) module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permission, which allows remote attackers to access the configuration pages via unspecified vectors. | |
| Modificada | Media (4.9) | 0.99% | — | Organic Groups Project Organic Groups | 29/4/2014 | 17/6/2026 | The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restrictions on nodes with all groups set to optional input via an empty group field. | |
| Modificada | Media (5.8) | 1.2% | — | Organic Groups Project Organic Groups | 29/4/2014 | 17/6/2026 | The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to bypass access restrictions and post to arbitrary groups via a group audience field, as demonstrated by the og_group_ref field. |