Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.21%—Rarathemes Book Landing Page21/6/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Book Landing Page.This issue affects Book Landing Page: from n/a through 1.2.3.
ModificadaMedia (5.3)0.37%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages21/6/202417/6/2026
The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to…
AplazadaMedia (6.8)0.87%—Web-settler Landing Page BuilderAI17/5/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Web-Settler Landing Page Builder – Free Landing Page Templates allows Path Traversal.This issue affects Landing Page Builder – Free Landing Page Templates: from n/a through 3.1.9.9.
AplazadaAlta (7.1)0.30%—Pluginops Landing Page BuilderAI17/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Reflected XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.8.
ModificadaAlta (7.5)0.52%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages10/4/202412/8/2026
Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.
AplazadaMedia (5.9)0.36%—Pluginops Landing Page BuilderAI29/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Stored XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.7.
AplazadaMedia (5.4)0.21%—Landingi Landing PagesAI29/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Landingi Landingi Landing Pages.This issue affects Landingi Landing Pages: from n/a through 3.1.1.
ModificadaMedia (5.3)0.45%—Fatcatapps Landing Page CAT15/2/202417/6/2026
The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.2. This makes it possible for unauthenticated attackers to access landing pages that may not be public.
ModificadaMedia (6.1)0.39%—Pluginops Landing Page Builder7/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.This issue affects Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages: from n/a through 1.5.1.5.
ModificadaAlta (8.8)0.23%—Keap Landing Pages10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Keap Keap Landing Pages plugin <= 1.4.2 versions.
ModificadaMedia (4.8)0.40%—Pluginops Landing Page Builder27/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps Landing Page Builder plugin <= 1.5.1.2 versions.
ModificadaMedia (6.1)0.46%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages5/6/202317/6/2026
The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.67%—Inboundnow Landing-pages6/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in Landing Pages Plugin up to 1.8.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.8.8 is able to address this issue. The…
ModificadaMedia (5.4)0.47%—Pluginops Landing Page Builder23/1/202317/6/2026
The Landing Page Builder WordPress plugin before 1.4.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such…
ModificadaMedia (5.4)0.53%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages16/1/202317/6/2026
The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as…
ModificadaMedia (5.4)1.1%💥 ExploitPluginops Landing Page17/1/202217/6/2026
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.
ModificadaAlta (8.8)2.9%—Inboundnow Wordpress Landing Pages18/10/201717/6/2026
The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.
ModificadaBaja (3.5)3.9%💥 ExploitLanding Pages Project Landing Pages27/5/201517/6/2026
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php.
ModificadaMedia (6.5)3.8%💥 ExploitLanding Pages Project Landing Pages27/5/201517/6/2026
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.
ModificadaAlta (7.5)2.5%—Landing Pages Project Landing Pages Plugin23/10/201317/6/2026
SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.php.
Orbitaley — Vulnerabilidades