Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

814 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.48%—Sso-masterAI8/9/202614/9/2026
An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.
AplazadaMedia (5.3)0.40%—Masteriyo LMSAI7/9/20268/9/2026
The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary…
AplazadaMedia (6.8)0.43%—Masteriyo LMSAI5/9/20268/9/2026
The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a…
AplazadaMedia (5.3)0.47%—Stylemixthemes Masterstudy LMSAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.
AplazadaBaja (3.8)0.32%—MasterstudylmsAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors.
AplazadaMedia (5.3)0.34%—MasterstudylmsAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, allowing unauthenticated users to read the titles and IDs of unpublished (draft, pending and private) courses.
AplazadaBaja (2.7)0.30%—MasterstudylmsAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' quiz questions, including the correct answers and explanations.
AplazadaMedia (5.3)0.34%—MasterstudylmsAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.
AplazadaMedia (4.3)0.27%—MasterstudylmsAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier.
AplazadaAlta (7.2)1.2%—Master-addons Master AddonsAI1/9/20261/9/2026
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.9 via the upload_template_kit function. This is due to incorrect authorization on the…
AplazadaMedia (4.7)0.29%—Stylmind Masterstudies LMSAI29/8/202631/8/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.
AplazadaBaja (2.7)0.30%—Stylemixthemes Masterstudy LMSAI29/8/202631/8/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs.
AplazadaMedia (4.8)0.22%—MasterstudylmsAI29/8/202631/8/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token…
AplazadaBaja (2.7)0.30%—Quizandsurveymaster Quiz AND Survey MasterAI28/8/202628/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.
AplazadaAlta (8.6)0.53%—Stylemixthemes Masterstudy LMSAI24/8/202626/8/2026
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
AplazadaAlta (7.1)0.25%—TourmasterAI24/8/202624/8/2026
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
AplazadaAlta (7.5)0.43%—Notification MasterAI24/8/202624/8/2026
Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More <= 1.7.1 versions.
AplazadaBaja (2.7)0.30%—Expressivequiz Quiz AND Survey MasterAI19/8/202626/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient…
AplazadaBaja (2.7)0.28%—Quizandsurveymaster Quiz AND Survey MasterAI19/8/202626/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.
AplazadaCrítica (9.8)0.52%—Masteriyo - LMSAI18/8/202620/8/2026
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
AplazadaMedia (6.5)0.34%—MasterstudylmsAI18/8/202620/8/2026
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
AplazadaMedia (6.3)0.26%—Masterstudy LMSAI18/8/202620/8/2026
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
AplazadaAlta (8.8)0.66%—T-systems International Gmbh ImagemasterAI17/8/20269/9/2026
File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.
AplazadaMedia (6.1)0.25%—Masteriyo LMSAI16/8/202626/8/2026
The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any visitor of the affected page, including…
AplazadaMedia (6.5)0.45%—Quizandsurveymaster Quiz AND Survey MasterAI16/8/202620/8/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…