Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.21% | — | Rarathemes Book Landing Page | 21/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Book Landing Page.This issue affects Book Landing Page: from n/a through 1.2.3. | |
| Modificada | Media (5.3) | 0.37% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 21/6/2024 | 17/6/2026 | The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.8) | 0.87% | — | Web-settler Landing Page BuilderAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Web-Settler Landing Page Builder – Free Landing Page Templates allows Path Traversal.This issue affects Landing Page Builder – Free Landing Page Templates: from n/a through 3.1.9.9. | |
| Aplazada | Alta (7.1) | 0.30% | — | Pluginops Landing Page BuilderAI | 17/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Reflected XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.8. | |
| Modificada | Alta (7.5) | 0.52% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 10/4/2024 | 12/8/2026 | Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5. | |
| Aplazada | Media (5.9) | 0.36% | — | Pluginops Landing Page BuilderAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Stored XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.7. | |
| Aplazada | Media (5.4) | 0.21% | — | Landingi Landing PagesAI | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Landingi Landingi Landing Pages.This issue affects Landingi Landing Pages: from n/a through 3.1.1. | |
| Modificada | Media (5.3) | 0.45% | — | Fatcatapps Landing Page CAT | 15/2/2024 | 17/6/2026 | The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.2. This makes it possible for unauthenticated attackers to access landing pages that may not be public. | |
| Modificada | Media (6.1) | 0.39% | — | Pluginops Landing Page Builder | 7/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.This issue affects Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages: from n/a through 1.5.1.5. | |
| Modificada | Alta (8.8) | 0.23% | — | Keap Landing Pages | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Keap Keap Landing Pages plugin <= 1.4.2 versions. | |
| Modificada | Media (4.8) | 0.40% | — | Pluginops Landing Page Builder | 27/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps Landing Page Builder plugin <= 1.5.1.2 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 5/6/2023 | 17/6/2026 | The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.67% | — | Inboundnow Landing-pages | 6/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Landing Pages Plugin up to 1.8.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.8.8 is able to address this issue. The… | |
| Modificada | Media (5.4) | 0.47% | — | Pluginops Landing Page Builder | 23/1/2023 | 17/6/2026 | The Landing Page Builder WordPress plugin before 1.4.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Media (5.4) | 0.53% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 16/1/2023 | 17/6/2026 | The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as… | |
| Modificada | Media (5.4) | 1.1% | 💥 Exploit | Pluginops Landing Page | 17/1/2022 | 17/6/2026 | The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page. | |
| Modificada | Alta (8.8) | 2.9% | — | Inboundnow Wordpress Landing Pages | 18/10/2017 | 17/6/2026 | The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter. | |
| Modificada | Baja (3.5) | 3.9% | 💥 Exploit | Landing Pages Project Landing Pages | 27/5/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php. | |
| Modificada | Media (6.5) | 3.8% | 💥 Exploit | Landing Pages Project Landing Pages | 27/5/2015 | 17/6/2026 | SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php. | |
| Modificada | Alta (7.5) | 2.5% | — | Landing Pages Project Landing Pages Plugin | 23/10/2013 | 17/6/2026 | SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.php. |