Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Social Login AND RegisterAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. | |
| Pendiente de análisis | Media (5.7) | 0.22% | — | Drupal Disable Login PageAI | 25/8/2026 | 2/9/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4. | |
| Pendiente de análisis | Media (5.7) | 0.19% | — | Drupal Email Login OTPAI | 25/8/2026 | 28/8/2026 | Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. | |
| Aplazada | Crítica (10) | 0.60% | — | Miniorange Saml SSOAIMiniorange Saml SP Single Sign ON Login With AdfsAIMiniorange Saml SP Single Sign ON Saml SSO Login With Google AppsAIJoomlaAI | 25/8/2026 | 8/9/2026 | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the mo_saml_validate_signature() function performing a… | |
| Aplazada | Alta (8.7) | 0.43% | — | Getgrav Grav-plugin-loginAIGetgrav GravAI | 25/8/2026 | 16/9/2026 | The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in classes/Controller.php (taskReset()) and login.php (activation handler). Because the token-submission endpoint… | |
| Aplazada | Crítica (9.3) | 0.34% | — | Getgrav Grav-plugin-loginAI | 25/8/2026 | 31/8/2026 | The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account, while allowing registration to proceed… | |
| Aplazada | Crítica (9.3) | 0.51% | — | Getgrav GravAIGetgrav LoginAI | 25/8/2026 | 31/8/2026 | Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without… | |
| Aplazada | Crítica (10) | 0.41% | — | Miniorange Oauth ClientAIMiniorange Oauth Single Sign ON Oidc SSOAIMiniorange Login With Keycloak Oauth Single Sign ON SSOAIMiniorange Single Sign ON FOR Educational InstitutesAI | 24/8/2026 | 8/9/2026 | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Smilepass Selfie LoginAI | 22/8/2026 | 26/8/2026 | The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators. | |
| Aplazada | Crítica (9.8) | 0.63% | — | Soclever Social Login Sharing Buttons With AnalyticsAI | 22/8/2026 | 26/8/2026 | The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators.… | |
| Aplazada | Crítica (9.8) | 0.50% | — | WP Social Media LoginAI | 22/8/2026 | 26/8/2026 | The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address. | |
| Aplazada | Baja (3.7) | 0.26% | — | Limitloginattempts Limit Login Attempts ReloadedAI | 21/8/2026 | 26/8/2026 | The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway. | |
| Aplazada | Alta (8.5) | 0.36% | — | Persistent LoginAI | 20/8/2026 | 20/8/2026 | Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Login Registration SystemAI | 20/8/2026 | 21/8/2026 | A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database Backup Handler. This manipulation causes files or directories accessible. The attack may be initiated remotely.… | |
| Aplazada | Media (5.4) | 0.18% | — | Phpcentral LoginAI | 19/8/2026 | 9/9/2026 | Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task accepts a top-level GET request through the TaskServiceProvider task: URI parameter without requiring a login-form nonce, an Origin check, or a Referer check. Under the… | |
| Aplazada | Alta (7.4) | 0.50% | — | Getgrav Grav LoginAI | 19/8/2026 | 9/9/2026 | Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that the pending-session user exists rather than requiring $user->authorized. After submitting a victim's correct password, an attacker can invoke… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Social Login AND RegisterAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Netweblogic Login With AjaxAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. | |
| Aplazada | Media (4.9) | 0.48% | — | User Login HistoryAI | 16/8/2026 | 20/8/2026 | The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to, and including, 2.1.7. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Simple JWT LoginAI | 16/8/2026 | 26/8/2026 | The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin… | |
| Aplazada | Media (4.4) | 0.33% | — | Weblizar Admin Custom LoginAI | 16/8/2026 | 20/8/2026 | The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Alta (8.1) | 0.75% | — | Ventraconnect Social Login Passwordless LoginAI | 12/8/2026 | 12/8/2026 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me… | |
| Aplazada | Alta (7.5) | 0.43% | — | Login AND Register FormsAI | 10/8/2026 | 26/8/2026 | The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'. | |
| Aplazada | Alta (8.1) | 0.38% | — | Login Register FormsAI | 10/8/2026 | 26/8/2026 | The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification code and the per-source attempt counter on client-controlled data, allowing unauthenticated attackers to reset the limit at will and brute-force the… | |
| Aplazada | Alta (8.1) | 0.38% | — | Login Register FormsAI | 10/8/2026 | 26/8/2026 | The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently… |