Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

108 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.3)0.52%—Joomshaper SP Page BuilderAI12/8/202626/8/2026
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.
AplazadaCrítica (9.2)0.51%—Joomshaper SP Page BuilderAI12/8/202626/8/2026
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.
AplazadaAlta (8.7)0.50%—Joomshaper SP Page BuilderAI7/8/202626/8/2026
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their…
AplazadaMedia (6.5)0.22%—Shapedplugin Location WeatherAI27/7/202627/7/2026
Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
AplazadaCrítica (9.8)0.51%—Joomshaper SP Page BuilderAI27/7/202628/7/2026
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.
AplazadaAlta (8.2)0.38%—Joomshaper SP Page BuilderAI27/7/202627/7/2026
Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.
AplazadaCrítica (9.2)0.39%—Joomshaper SP Page BuilderAI27/7/202612/8/2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.
AplazadaCrítica (9.2)0.40%—Joomshaper SP Page BuilderAI27/7/202627/7/2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.
AplazadaCrítica (9.3)1.0%💥 ExploitJoomshaper Easy StoreAI23/7/202623/7/2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.
AplazadaCrítica (9.2)0.42%—Joomshaper Easy StoreAI23/7/202623/7/2026
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.
AplazadaAlta (8.7)0.43%—Joomshaper Easy StoreAI23/7/202623/7/2026
Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.
AplazadaAlta (7.2)0.54%—Shapedplugin Real TestimonialsAI13/7/202613/7/2026
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.
AplazadaAlta (7.5)0.43%—Shapedsmart Smart Post Show PROAIReal Testimonials PROAIProduct Slider FOR Woocommerce PROAI24/6/202625/6/2026
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for…
AplazadaCrítica (9.5)4.9%💥 ExploitJoomshaper SP LMSAI20/6/202622/6/2026
SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.
AnalizadaAlta (8.8)0.49%—Joomshaper Standard PRO Movie Database19/6/202619/8/2026
Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to…
AplazadaCrítica (10)2.0%💥 ExploitShapedplugin LLC Product Slider PRO FOR WoocommerceAI5/6/202623/7/2026
Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.
AplazadaAlta (8.7)0.33%—Hape PKHAI29/5/202621/7/2026
HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target record's id. The admin/modul/mod_pengurus/aksi_pengurus.php (module=pengurus&act=hapus) and…
AplazadaAlta (8.8)0.33%—Hape PKHAI29/5/202621/7/2026
HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-perdesa-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract sensitive…
AplazadaAlta (8.8)0.33%—Hape PKHAI29/5/202621/7/2026
HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter sent to lap-anggota-kelompok-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract…
AplazadaAlta (8.7)0.52%—Hape PKHAI29/5/202621/7/2026
HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.
AplazadaMedia (6.9)0.18%—Hape PKHAI29/5/202621/7/2026
HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft malicious forms targeting the aksi_user.php script with parameters like id_user, password, and level to modify admin…
AplazadaAlta (8.8)0.33%—Hape PKHAI29/5/202621/7/2026
HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while authenticated users can exploit the pengurus,…
AplazadaMedia (4.3)0.35%—Shapedplugin Location WeatherAI22/5/202624/7/2026
The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `lwp_clean_weather_transients()` functions in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.2)0.69%—Shapedplugin Smart Post ShowAI14/4/202617/6/2026
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenticated attackers, with…
AplazadaBaja (2.7)0.22%—Shapeshift Shopengine Elementor Woocommerce Builder AddonAI25/10/202517/6/2026
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it…
Orbitaley — Vulnerabilidades