Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.33% | — | Evoluted PHP Directory Listing ScriptAI | 9/6/2026 | 23/7/2026 | Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HTML title element and inside anchor href attributes in the breadcrumb navigation. Attackers can inject arbitrary… | |
| Aplazada | Alta (8.8) | 0.27% | — | Listing HUB CMSAI | 4/6/2026 | 22/7/2026 | Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to pages.php with crafted id values using error-based SQL injection techniques to extract database… | |
| Aplazada | Media (6.5) | 0.44% | — | Radiustheme Classified ListingAI | 1/6/2026 | 22/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8. | |
| Aplazada | Media (4.3) | 0.45% | — | Radiustheme Classified ListingAI | 15/5/2026 | 17/6/2026 | The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.27% | — | Elated-themes Elated ListingAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Elated-Themes Elated Listing eltd-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elated Listing: from n/a through <= 1.4. | |
| Aplazada | Alta (7.1) | 0.26% | — | Cridio ListingproAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro-plugin allows Reflected XSS.This issue affects ListingPro: from n/a through <= 2.9.8. | |
| Aplazada | Media (4.9) | 0.49% | — | Stylemixthemes UlistingAI | 5/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Stylemix uListing ulisting allows Path Traversal.This issue affects uListing: from n/a through <= 2.2.0. | |
| Aplazada | Media (6.5) | 0.37% | — | Radiustheme Classified ListingAI | 5/3/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme Classified Listing classified-listing allows Retrieve Embedded Sensitive Data.This issue affects Classified Listing: from n/a through <= 5.3.4. | |
| Aplazada | Alta (7.2) | 0.60% | — | Stylemixthemes UlistingAI | 26/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <= 2.2.0. | |
| Aplazada | Media (5.9) | 0.32% | — | Themeglow Jobboard JOB ListingAIThemeglow Job-board-lightAI | 20/2/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in themeglow JobBoard Job listing job-board-light allows Retrieve Embedded Sensitive Data.This issue affects JobBoard Job listing: from n/a through <= 1.2.8. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Clasifico ListingAI | 19/2/2026 | 17/6/2026 | The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin allowing users who are registering new accounts to set their own role by supplying the 'listing_user_role' parameter. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Prime Listing ManagerAI | 12/2/2026 | 17/6/2026 | The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret. | |
| Aplazada | Media (6.4) | 0.28% | — | Events Listing WidgetAI | 6/2/2026 | 17/6/2026 | The Events Listing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Event URL' parameter in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Analizada | Baja (2) | 0.26% | — | Projectworlds House Rental AND Property Listing Project | 30/1/2026 | 17/6/2026 | A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknown code of the file /app/sms.php. This manipulation of the argument Message causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the… | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins ListinghubAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins ListingHub listinghub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingHub: from n/a through <= 1.2.7. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Hotel ListingAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Hotel Listing hotel-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Listing: from n/a through <= 1.4.2. | |
| Aplazada | Alta (7.1) | 0.21% | — | E-plugins Hotel ListingAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Hotel Listing hotel-listing allows Reflected XSS.This issue affects Hotel Listing: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Cridiostudio Listingpro ReviewsAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro Reviews listingpro-reviews allows Reflected XSS.This issue affects ListingPro Reviews: from n/a through < 2.9.11. | |
| Aplazada | Media (6.5) | 0.32% | — | Realestateconnected Easy Property ListingsAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.20. | |
| Aplazada | Alta (7.6) | 0.37% | — | E-plugins Hotel ListingAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Hotel Listing hotel-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Listing: from n/a through <= 1.4.2. | |
| Aplazada | Alta (7.1) | 0.21% | — | E-plugins ListinghubAI | 8/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins ListingHub listinghub allows Reflected XSS.This issue affects ListingHub: from n/a through 1.2.6. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Themesuite Automotive ListingsAI | 8/1/2026 | 5/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allows Blind SQL Injection.This issue affects Automotive Listings: from n/a through <= 18.6. | |
| Analizada | Media (5.5) | 0.42% | — | Projectworlds House Rental AND Property Listing Project | 7/1/2026 | 17/6/2026 | A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been… | |
| Modificada | Baja (1.9) | 0.25% | — | Projectworlds House Rental AND Property Listing Project | 7/1/2026 | 17/6/2026 | A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /app/complaint.php. The manipulation of the argument Name results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Media (4.3) | 0.17% | — | Easy Property Listings XML CSV ImportAI | 30/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Merv Barrett Import into Easy Property Listings easy-property-listings-xml-csv-import allows Cross Site Request Forgery.This issue affects Import into Easy Property Listings: from n/a through <= 2.2.1. |