Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.35% | — | Russelljamieson Footer Putter | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter allows Stored XSS.This issue affects Footer Putter: from n/a through 1.17. | |
| Modificada | Media (5.4) | 0.38% | — | Benjaminzekavica Easy SVG Support | 29/1/2024 | 17/6/2026 | The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Modificada | Alta (7.2) | 0.77% | — | Benjaminrojas WP Editor | 16/1/2024 | 17/6/2026 | The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings. | |
| Modificada | Crítica (9.8) | 0.55% | — | Jamieblomerus Unofficial Mobile Bankid Integration | 27/12/2023 | 17/6/2026 | Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability, specifically impacting scenarios where an… | |
| Modificada | Alta (8.8) | 0.25% | — | Ulfbenjaminsson Wp-dtree | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Ulfbenjaminsson Wp-dtree | 29/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Savoirfairelinux Jami | 14/7/2023 | 17/6/2026 | Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows. This allows an attacker to send a custom HTML anchor tag to pass a string value to the Windows QRC Handler through the Jami messenger. | |
| Modificada | Media (5.5) | 0.21% | — | Savoirfairelinux Jami | 14/7/2023 | 17/6/2026 | The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts special characters into the field. When present, these special characters, make it so the application cannot create the signature for the user and results in a local denial of service to the… | |
| Modificada | Crítica (9.8) | 2.0% | — | Benjaminrojas WP Editor | 14/8/2019 | 17/6/2026 | The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions. | |
| Modificada | Alta (8.8) | 0.68% | — | Benjaminrojas WP Editor | 14/8/2019 | 17/6/2026 | The wp-editor plugin before 1.2.6 for WordPress has CSRF. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Benjamin Arnaudetr Ginkgocms | 20/8/2013 | 16/6/2026 | SQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang parameter to index.php. | |
| Modificada | Media (4.3) | 1.8% | — | Benjamin Mack SEO Basics | 17/11/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Basic SEO Features (seo_basics) extension before 0.8.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Jamit JOB Board | 15/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in jobs/index.php in Jamit Job Board 3.0 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Benjamin Curtis Phpbugtracker | 1/6/2009 | 16/6/2026 | SQL injection vulnerability in include.php in phpBugTracker 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Benjamin Curtis Phpbugtracker | 1/6/2009 | 16/6/2026 | SQL injection vulnerability in index.php in phpBugTracker 1.0.3 allows remote attackers to execute arbitrary SQL commands via the password parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Jamit Software Jamit JOB Board | 1/12/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL commands via the show_emp parameter. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Benjamin KUZ Dynamic MP3 Lister | 23/9/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) currentpath, (2) invert, (3) search, and (4) sort parameters. | |
| Modificada | Media (4.3) | 1.3% | — | Benjamin Pasero AND Tobias Eichert Rssowl | 13/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Benjamin Pasero and Tobias Eichert RSSOwl allow remote attackers to inject arbitrary web script or HTML via a web feed, as demonstrated by certain test cases of the Robert Auger and Caleb Sima RSS and Atom feed reader test suite. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Jamit JOB Board | 14/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the vendor has disputed this issue, saying "The vulnerability is without any basis and did not actually work." CVE has not verified either the vendor or… | |
| Modificada | Alta (7.5) | 7.1% | 💥 Exploit | Benjamin Lefevre Dobermann Forum | 31/12/2002 | 16/6/2026 | Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the "subpath" variablein (1) entete.php, (2) enteteacceuil.php, (3) index.php, or (4) newtopic.php. |