Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

300 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Mapsteps UG Ultimate Dashboard PROAI18/8/20265/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Dashboard Ultimate Dashboard Pro ultimate-dashboard-pro allows DOM-Based XSS.This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2.
AplazadaMedia (6.5)0.34%—WP Maps PROAI9/8/202626/8/2026
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary…
AplazadaAlta (7.5)0.48%—WP Maps PROAI9/8/202626/8/2026
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources,…
AplazadaMedia (6.5)0.41%—Weplugins WP MapsAI7/8/202626/8/2026
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
AplazadaAlta (8.8)0.53%—Weplugins WP MapsAI7/8/202626/8/2026
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.
AplazadaAlta (7.5)0.43%—Mapster WP MapsAI1/8/202626/8/2026
The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauthenticated users to retrieve the title and full content of any post regardless of its status, including unpublished (draft, pending, private, and trashed) posts.
AplazadaMedia (4.3)0.29%—Flippercode WP MapsAI31/7/202612/8/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6.
AplazadaBaja (3.7)0.28%—WP GO MapsAI31/7/202626/8/2026
The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
AplazadaCrítica (9.3)0.40%—MapsvgAI27/7/202627/7/2026
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
AplazadaMedia (6.4)0.32%—MapsvgAI24/7/202629/9/2026
The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficient input sanitization and output escaping on user supplied attributes within the map options. This makes it possible for authenticated attackers, with contributor-level…
AplazadaMedia (5.1)0.44%—Phoca MapsAI23/7/202624/7/2026
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vulnerability.
AplazadaCrítica (9.1)0.50%—MapsvgAI23/7/202623/7/2026
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
AplazadaAlta (8.5)0.36%—MapsvgAI23/7/202623/7/2026
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
AplazadaAlta (8.5)0.36%—MapsvgAI23/7/202623/7/2026
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
AplazadaMedia (6.5)0.22%—MapsvgAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
AplazadaCrítica (9.3)0.40%—MapsvgAI23/7/202623/7/2026
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
AplazadaAlta (7.1)0.25%—WP Google Maps PROAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
AplazadaMedia (5.3)0.31%—WP GO MapsAI23/7/202623/7/2026
Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
AplazadaAlta (7.2)1.1%—MapsvgAI21/7/202622/7/2026
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that prevents file validation from taking place. This makes it possible for authenticated…
AplazadaAlta (7.1)0.25%—Google Maps CPAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions.
AplazadaAlta (7.1)0.25%—Mappress MapsAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.
AplazadaMedia (5.3)0.38%—WP GO MapsAI19/6/202624/6/2026
The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create arbitrary…
AplazadaCrítica (9.3)0.40%—Weplugins WP MapsAI15/6/202617/6/2026
Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
AplazadaCrítica (9.8)0.48%—WP Maps PROAI15/6/202623/7/2026
The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.
AplazadaMedia (5.3)0.76%—WP GO MapsAI15/6/202623/7/2026
The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields…