Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.35%—Russelljamieson Footer Putter1/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter allows Stored XSS.This issue affects Footer Putter: from n/a through 1.17.
ModificadaMedia (5.4)0.38%—Benjaminzekavica Easy SVG Support29/1/202417/6/2026
The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
ModificadaAlta (7.2)0.77%—Benjaminrojas WP Editor16/1/202417/6/2026
The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.
ModificadaCrítica (9.8)0.55%—Jamieblomerus Unofficial Mobile Bankid Integration27/12/202317/6/2026
Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability, specifically impacting scenarios where an…
ModificadaAlta (8.8)0.25%—Ulfbenjaminsson Wp-dtree9/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions.
ModificadaMedia (6.1)0.38%—Ulfbenjaminsson Wp-dtree29/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions.
ModificadaMedia (5.4)0.38%—Savoirfairelinux Jami14/7/202317/6/2026
Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows. This allows an attacker to send a custom HTML anchor tag to pass a string value to the Windows QRC Handler through the Jami messenger.
ModificadaMedia (5.5)0.21%—Savoirfairelinux Jami14/7/202317/6/2026
The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts special characters into the field. When present, these special characters, make it so the application cannot create the signature for the user and results in a local denial of service to the…
ModificadaCrítica (9.8)2.0%—Benjaminrojas WP Editor14/8/201917/6/2026
The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
ModificadaAlta (8.8)0.68%—Benjaminrojas WP Editor14/8/201917/6/2026
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
ModificadaAlta (7.5)2.2%💥 ExploitBenjamin Arnaudetr Ginkgocms20/8/201316/6/2026
SQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang parameter to index.php.
ModificadaMedia (4.3)1.8%—Benjamin Mack SEO Basics17/11/201216/6/2026
Cross-site scripting (XSS) vulnerability in Basic SEO Features (seo_basics) extension before 0.8.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.5%💥 ExploitJamit JOB Board15/1/201016/6/2026
Cross-site scripting (XSS) vulnerability in jobs/index.php in Jamit Job Board 3.0 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.
ModificadaAlta (7.5)1.0%—Benjamin Curtis Phpbugtracker1/6/200916/6/2026
SQL injection vulnerability in include.php in phpBugTracker 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)0.99%💥 ExploitBenjamin Curtis Phpbugtracker1/6/200916/6/2026
SQL injection vulnerability in index.php in phpBugTracker 1.0.3 allows remote attackers to execute arbitrary SQL commands via the password parameter.
ModificadaAlta (7.5)1.0%💥 ExploitJamit Software Jamit JOB Board1/12/200816/6/2026
SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL commands via the show_emp parameter.
ModificadaMedia (4.3)1.4%💥 ExploitBenjamin KUZ Dynamic MP3 Lister23/9/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) currentpath, (2) invert, (3) search, and (4) sort parameters.
ModificadaMedia (4.3)1.3%—Benjamin Pasero AND Tobias Eichert Rssowl13/9/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Benjamin Pasero and Tobias Eichert RSSOwl allow remote attackers to inject arbitrary web script or HTML via a web feed, as demonstrated by certain test cases of the Robert Auger and Caleb Sima RSS and Atom feed reader test suite.
ModificadaAlta (7.5)1.2%💥 ExploitJamit JOB Board14/12/200516/6/2026
SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the vendor has disputed this issue, saying "The vulnerability is without any basis and did not actually work." CVE has not verified either the vendor or…
ModificadaAlta (7.5)7.1%💥 ExploitBenjamin Lefevre Dobermann Forum31/12/200216/6/2026
Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the "subpath" variablein (1) entete.php, (2) enteteacceuil.php, (3) index.php, or (4) newtopic.php.
Orbitaley — Vulnerabilidades