Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.53% | — | Colorlib Coming Soon & Maintenance Mode | 20/3/2024 | 17/6/2026 | The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.99 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page contents via REST API thus bypassing maintenance mode protection provided… | |
| Aplazada | Media (5.3) | 0.59% | — | Dazzler Coming Soon Under Construction Maintenance ModeAI | 20/3/2024 | 17/6/2026 | The Coming Soon, Under Construction & Maintenance Mode By Dazzler plugin for WordPress is vulnerable to maintenance mode bypass in all versions up to, and including, 2.1.2. This is due to the plugin relying on the REQUEST_URI to determine if the page being accesses is an admin area. This makes it possible for… | |
| Modificada | Media (5.3) | 0.53% | — | Helderk Maintenance Mode | 5/3/2024 | 17/6/2026 | The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content via API thus bypassing the content protection provided by the plugin. | |
| Modificada | Media (5.3) | 0.46% | — | Awplife Coming Soon Maintenance Mode | 29/2/2024 | 17/6/2026 | The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content thus bypassing the protection provided by the plugin. | |
| Modificada | Media (5.3) | 0.47% | — | Acurax Under Construction / Maintenance Mode | 28/2/2024 | 17/6/2026 | The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 via the REST API. This makes it possible for unauthenticated attackers to obtain the contents of posts and pages when maintenance mode is active thus… | |
| Modificada | Media (5.3) | 0.46% | — | Wpshopmart Coming Soon Page & Maintenance Mode | 28/2/2024 | 17/6/2026 | The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an improperly implemented URL check in the wpsm_coming_soon_redirect function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to view a site with… | |
| Modificada | Media (6.5) | 0.49% | — | Acurax Under Construction / Maintenance Mode | 28/2/2024 | 17/6/2026 | The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.6 via the 'acx_csma_subscribe_ajax' function. This can allow authenticated attackers to extract sensitive data such as names and email addresses of subscribed… | |
| Modificada | Media (5.3) | 0.68% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 5/2/2024 | 17/6/2026 | The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance… | |
| Modificada | Media (4.8) | 0.39% | — | Wpexperts Rocket Maintenance Mode & Coming Soon Page | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpexpertsio Rocket Maintenance Mode & Coming Soon Page allows Stored XSS.This issue affects Rocket Maintenance Mode & Coming Soon Page: from n/a through 4.3. | |
| Modificada | Media (6.1) | 0.41% | — | Acurax Under Construction / Maintenance Mode | 16/11/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Acurax Under Construction / Maintenance Mode from Acurax plugin <= 2.6 versions. | |
| Modificada | Crítica (9.8) | 0.68% | — | Weblizar Responsive Coming Soon & Maintenance Mode | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar Coming Soon Page – Responsive Coming Soon & Maintenance Mode allows SQL Injection.This issue affects Coming Soon Page – Responsive Coming Soon & Maintenance Mode: from n/a through 1.5.9. | |
| Modificada | Media (4.3) | 0.48% | — | Wpconcern Coming Soon & Maintenance Mode Page | 12/7/2023 | 17/6/2026 | The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to missing or incorrect nonce validation on the save_meta_box() function. This makes it possible for unauthenticated attackers to save meta boxes via a forged… | |
| Modificada | Alta (8.8) | 0.45% | — | Wpconcern Nifty Coming Soon & Maintenance Mode Page | 7/6/2023 | 17/6/2026 | The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to confusing logic functions missing or having incorrect nonce validation. This makes it possible for unauthenticated attackers to gain and perform otherwise… | |
| Modificada | Media (6.1) | 0.77% | — | Wpshopmart Coming Soon Page & Maintenance Mode | 7/6/2023 | 17/6/2026 | The WordPress Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logo_width, logo_height, rcsp_logo_url, home_sec_link_txt, rcsp_headline and rcsp_description parameters in versions up to, and including, 1.8.1 due to insufficient input sanitization and output… | |
| Modificada | Media (5.3) | 0.81% | — | Wpshopmart Coming Soon Page & Maintenance Mode | 7/6/2023 | 17/6/2026 | The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions up to, and including 1.8.1 due to missing capability checks in the ~/functions/data-reset-post.php file which makes it possible for unauthenticated attackers to trigger a plugin settings reset. | |
| Modificada | Media (4.8) | 0.46% | — | Duplicator EZP Maintenance Mode | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Maintenance Mode plugin <= 1.0.1 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Obox Launchpad - Coming Soon & Maintenance Mode Plugin | 17/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Obox Themes Launchpad – Coming Soon & Maintenance Mode plugin <= 1.0.13 versions. | |
| Modificada | Media (4.8) | 0.54% | — | Obox Launchpad - Coming Soon & Maintenance Mode Plugin | 13/1/2023 | 17/6/2026 | The Launchpad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Modificada | Media (6.5) | 0.52% | — | Themeisle WP Maintenance Mode & Coming Soon | 11/7/2022 | 17/6/2026 | The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack | |
| Modificada | Media (4.8) | 0.59% | — | Colorlib Coming Soon & Maintenance Mode | 20/6/2022 | 17/6/2026 | The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered_html is disallowed (for example in multisite setup) | |
| Modificada | Media (4.3) | 0.47% | — | Wpdevart Coming Soon AND Maintenance Mode | 21/2/2022 | 17/6/2026 | The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack | |
| Modificada | Media (4.3) | 0.35% | — | Wpdevart Coming Soon AND Maintenance Mode | 21/2/2022 | 17/6/2026 | The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users | |
| Modificada | Media (4.8) | 0.59% | — | Dazzlersoftware Coming Soon, Under Construction & Maintenance Mode BY Dazzler | 1/11/2021 | 17/6/2026 | The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored… | |
| Modificada | Media (5.4) | 0.62% | — | Wpdevart Coming Soon AND Maintenance Mode | 11/10/2021 | 17/6/2026 | The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to stored XSS. | |
| Modificada | Media (4.8) | 0.71% | — | Yithemes Yith Maintenance Mode | 27/9/2021 | 17/6/2026 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the 1.3.7 version to 1.3.8. Vulnerable parameters: 1 - "Newsletter" tab,… |