Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
118 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.34% | — | Team Members Multi Language Supported Team PluginAI | 30/6/2026 | 30/6/2026 | The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Pendiente de análisis | Alta (8.5) | 0.19% | — | Amazon Language ServersAI | 23/6/2026 | 23/6/2026 | Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate this issue, users… | |
| Pendiente de análisis | Alta (8.5) | 0.23% | — | Amazon Language ServersAI | 23/6/2026 | 23/6/2026 | Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the… | |
| Analizada | Alta (8.7) | 0.50% | — | Angular Language Service | 22/6/2026 | 26/6/2026 | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS Code extension configures the tooltip Markdown renderer with the isTrusted: true option (located in client/src/client.ts). This setting instructs VS Code to trust all… | |
| Analizada | Alta (8.7) | 0.24% | — | Angular Language Service | 22/6/2026 | 26/6/2026 | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Language Service VS Code extension reads the custom TypeScript SDK paths typescript.tsdk and js/ts.tsdk.path directly from workspace configurations (.vscode/settings.json)… | |
| Aplazada | Alta (8.8) | 0.42% | — | Falang MultilanguageAI | 17/6/2026 | 17/6/2026 | Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions. | |
| Analizada | Alta (8.4) | 0.24% | — | Vercel Turborepo Language Server Protocol | 15/5/2026 | 17/6/2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and task runs. A malicious… | |
| Aplazada | Media (6.4) | 0.43% | — | Quran Live MultilanguageAI | 22/4/2026 | 17/6/2026 | The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cheikh' and 'lang' shortcode attributes in all versions up to, and including, 1.0.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The quran_live_render()… | |
| Aplazada | Media (5.9) | 0.17% | — | Pascal Birchler Preferred LanguagesAI | 6/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birchler Preferred Languages allows DOM-Based XSS.This issue affects Preferred Languages: from n/a through 2.2.2. | |
| Aplazada | Media (5.5) | 0.36% | — | User Language SwitchAI | 14/2/2026 | 17/6/2026 | The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web… | |
| Aplazada | Media (4.4) | 0.25% | — | User Language SwitchAI | 14/2/2026 | 17/6/2026 | The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_language_switch' parameter in all versions up to, and including, 1.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.29% | — | Bestwebsoft MultilanguageAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in bestwebsoft Multilanguage by BestWebSoft multilanguage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multilanguage by BestWebSoft: from n/a through <= 1.5.2. | |
| Analizada | Alta (8.8) | 0.71% | — | Microsoft Azure Language | 18/12/2025 | 17/6/2026 | Custom Question Answering Elevation of Privilege Vulnerability | |
| Aplazada | Alta (8.8) | 0.38% | — | Sbouey Falang MultilanguageAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in sbouey Falang multilanguage falang allows Object Injection.This issue affects Falang multilanguage: from n/a through <= 1.3.65. | |
| Aplazada | Media (4.4) | 0.23% | — | Bootstrap Multi Language Responsive PortfolioAI | 4/11/2025 | 17/6/2026 | The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Alta (8.8) | 0.35% | — | Wikimedia Mediawiki - Languageselector ExtensionAI | 20/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The Wikimedia Foundation Mediawiki - LanguageSelector Extension allows Code Injection.This issue affects Mediawiki - LanguageSelector Extension: from master before 1.39. | |
| Aplazada | Media (6.4) | 0.19% | — | A Simple Multilanguage PluginAI | 3/10/2025 | 17/6/2026 | The A Simple Multilanguage Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'asmp-switcher' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.21% | — | Michel - Xiligroup DEV Xili-languageAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-language xili-language allows DOM-Based XSS.This issue affects xili-language: from n/a through <= 2.21.3. | |
| Aplazada | Alta (7.1) | 0.23% | — | Webilop User Language SwitchAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webilop User Language Switch user-language-switch allows Reflected XSS.This issue affects User Language Switch: from n/a through <= 1.6.10. | |
| Modificada | Media (6.1) | 0.31% | — | Languagesloth THE Language Sloth | 1/8/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description text field. | |
| Analizada | Crítica (9.8) | 0.41% | — | Gitlab Language Server | 28/7/2025 | 17/6/2026 | Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution | |
| Aplazada | Alta (7.5) | 0.40% | — | Augustinfotech Multi-language Responsive Contact FormAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in August Infotech Multi-language Responsive Contact Form responsive-contact-form allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Multi-language Responsive Contact Form: from n/a through <= 2.8. | |
| Aplazada | Media (4.3) | 0.14% | — | Sbouey Falang MultilanguageAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sbouey Falang multilanguage falang allows Cross Site Request Forgery.This issue affects Falang multilanguage: from n/a through <= 1.3.61. | |
| Aplazada | Media (5.9) | 0.27% | — | Karim42 Quran Multilanguage Text & AudioAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karim42 Quran multilanguage Text & Audio quran-text-multilanguage allows Stored XSS.This issue affects Quran multilanguage Text & Audio: from n/a through <= 2.3.23. | |
| Aplazada | Alta (7.1) | 0.15% | — | Alexander Rauscha MlanguageAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alexander Rauscha mLanguage mlanguage allows Stored XSS.This issue affects mLanguage: from n/a through <= 1.6.1. |