Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.52% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name. | |
| Aplazada | Crítica (9.2) | 0.51% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system. | |
| Aplazada | Alta (8.7) | 0.50% | — | Joomshaper SP Page BuilderAI | 7/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their… | |
| Aplazada | Media (6.5) | 0.22% | — | Shapedplugin Location WeatherAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 28/7/2026 | Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms. | |
| Aplazada | Alta (8.2) | 0.38% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector. | |
| Aplazada | Crítica (9.2) | 0.39% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 12/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector. | |
| Aplazada | Crítica (9.2) | 0.40% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector. | |
| Aplazada | Crítica (9.3) | 1.0% | 💥 Exploit | Joomshaper Easy StoreAI | 23/7/2026 | 23/7/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions. | |
| Aplazada | Crítica (9.2) | 0.42% | — | Joomshaper Easy StoreAI | 23/7/2026 | 23/7/2026 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system. | |
| Aplazada | Alta (8.7) | 0.43% | — | Joomshaper Easy StoreAI | 23/7/2026 | 23/7/2026 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders. | |
| Aplazada | Alta (7.2) | 0.54% | — | Shapedplugin Real TestimonialsAI | 13/7/2026 | 13/7/2026 | Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15. | |
| Aplazada | Alta (7.5) | 0.43% | — | Shapedsmart Smart Post Show PROAIReal Testimonials PROAIProduct Slider FOR Woocommerce PROAI | 24/6/2026 | 25/6/2026 | Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for… | |
| Aplazada | Crítica (9.5) | 4.9% | 💥 Exploit | Joomshaper SP LMSAI | 20/6/2026 | 22/6/2026 | SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server. | |
| Analizada | Alta (8.8) | 0.49% | — | Joomshaper Standard PRO Movie Database | 19/6/2026 | 19/8/2026 | Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to… | |
| Aplazada | Crítica (10) | 2.0% | 💥 Exploit | Shapedplugin LLC Product Slider PRO FOR WoocommerceAI | 5/6/2026 | 23/7/2026 | Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4. | |
| Aplazada | Alta (8.7) | 0.33% | — | Hape PKHAI | 29/5/2026 | 21/7/2026 | HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target record's id. The admin/modul/mod_pengurus/aksi_pengurus.php (module=pengurus&act=hapus) and… | |
| Aplazada | Alta (8.8) | 0.33% | — | Hape PKHAI | 29/5/2026 | 21/7/2026 | HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-perdesa-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract sensitive… | |
| Aplazada | Alta (8.8) | 0.33% | — | Hape PKHAI | 29/5/2026 | 21/7/2026 | HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter sent to lap-anggota-kelompok-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract… | |
| Aplazada | Alta (8.7) | 0.52% | — | Hape PKHAI | 29/5/2026 | 21/7/2026 | HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server. | |
| Aplazada | Media (6.9) | 0.18% | — | Hape PKHAI | 29/5/2026 | 21/7/2026 | HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft malicious forms targeting the aksi_user.php script with parameters like id_user, password, and level to modify admin… | |
| Aplazada | Alta (8.8) | 0.33% | — | Hape PKHAI | 29/5/2026 | 21/7/2026 | HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while authenticated users can exploit the pengurus,… | |
| Aplazada | Media (4.3) | 0.35% | — | Shapedplugin Location WeatherAI | 22/5/2026 | 24/7/2026 | The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `lwp_clean_weather_transients()` functions in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.69% | — | Shapedplugin Smart Post ShowAI | 14/4/2026 | 17/6/2026 | The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (2.7) | 0.22% | — | Shapeshift Shopengine Elementor Woocommerce Builder AddonAI | 25/10/2025 | 17/6/2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it… |