Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Mapsteps UG Ultimate Dashboard PROAI | 18/8/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Dashboard Ultimate Dashboard Pro ultimate-dashboard-pro allows DOM-Based XSS.This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2. | |
| Aplazada | Media (6.5) | 0.34% | — | WP Maps PROAI | 9/8/2026 | 26/8/2026 | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary… | |
| Aplazada | Alta (7.5) | 0.48% | — | WP Maps PROAI | 9/8/2026 | 26/8/2026 | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources,… | |
| Aplazada | Media (6.5) | 0.41% | — | Weplugins WP MapsAI | 7/8/2026 | 26/8/2026 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service. | |
| Aplazada | Alta (8.8) | 0.53% | — | Weplugins WP MapsAI | 7/8/2026 | 26/8/2026 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server. | |
| Aplazada | Alta (7.5) | 0.43% | — | Mapster WP MapsAI | 1/8/2026 | 26/8/2026 | The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauthenticated users to retrieve the title and full content of any post regardless of its status, including unpublished (draft, pending, private, and trashed) posts. | |
| Aplazada | Media (4.3) | 0.29% | — | Flippercode WP MapsAI | 31/7/2026 | 12/8/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6. | |
| Aplazada | Baja (3.7) | 0.28% | — | WP GO MapsAI | 31/7/2026 | 26/8/2026 | The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
| Aplazada | Crítica (9.3) | 0.40% | — | MapsvgAI | 27/7/2026 | 27/7/2026 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | |
| Aplazada | Media (6.4) | 0.32% | — | MapsvgAI | 24/7/2026 | 29/9/2026 | The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficient input sanitization and output escaping on user supplied attributes within the map options. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (5.1) | 0.44% | — | Phoca MapsAI | 23/7/2026 | 24/7/2026 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vulnerability. | |
| Aplazada | Crítica (9.1) | 0.50% | — | MapsvgAI | 23/7/2026 | 23/7/2026 | Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | MapsvgAI | 23/7/2026 | 23/7/2026 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | MapsvgAI | 23/7/2026 | 23/7/2026 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | MapsvgAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | MapsvgAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | WP Google Maps PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | WP GO MapsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. | |
| Aplazada | Alta (7.2) | 1.1% | — | MapsvgAI | 21/7/2026 | 22/7/2026 | The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that prevents file validation from taking place. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.25% | — | Google Maps CPAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mappress MapsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions. | |
| Aplazada | Media (5.3) | 0.38% | — | WP GO MapsAI | 19/6/2026 | 24/6/2026 | The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create arbitrary… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Weplugins WP MapsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | WP Maps PROAI | 15/6/2026 | 23/7/2026 | The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access. | |
| Aplazada | Media (5.3) | 0.76% | — | WP GO MapsAI | 15/6/2026 | 23/7/2026 | The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields… |