Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

47 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.34%—Inisev Redirection3/4/202317/6/2026
The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.
ModificadaCrítica (9.8)1.2%—Smplredirectionsmanager Project Smplredirectionsmanager24/3/202317/6/2026
SQL injection vulnerability found in PrestaShop smplredirectionsmanager v.1.1.19 and before allow a remote attacker to gain privileges via the SmplTools::getMatchingRedirectionsFromPartscomponent.
ModificadaAlta (8.8)0.31%—Clogica SEO Redirection18/11/202217/6/2026
Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress.
ModificadaAlta (7.5)0.61%—Redirection-for-contact-form7 Redirection FOR Contact Form 711/10/202217/6/2026
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe.
ModificadaMedia (4.3)0.31%—Clogica SEO Redirection23/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 404 errors and redirection history.
ModificadaMedia (6.1)1.6%—Redirection-for-contact-form7 Redirection FOR Contact Form 74/7/202217/6/2026
The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting
ModificadaAlta (8.8)1.4%—Wp-buy SEO Redirection-301 Redirect Manager17/11/202117/6/2026
The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed
ModificadaMedia (4.8)0.62%—Clogica SEO Redirection Plugin17/5/202117/6/2026
The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads
ModificadaMedia (6.1)0.83%—Clogica SEO Redirection Plugin17/5/202117/6/2026
The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute.
ModificadaMedia (6.3)0.73%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to a…
ModificadaMedia (4.3)0.66%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.
ModificadaAlta (8.8)2.0%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.
ModificadaMedia (6.5)0.83%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.
ModificadaAlta (7.5)7.4%—Querysol Redirection FOR Contact Form 714/5/202117/6/2026
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.
ModificadaMedia (5.4)0.63%—Clogica SEO Redirection5/4/202117/6/2026
The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.
ModificadaMedia (6.1)0.92%—Redirection28/8/201916/6/2026
The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562.
ModificadaMedia (6.1)0.92%—Redirection28/8/201916/6/2026
The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562.
ModificadaMedia (6.1)0.91%—Clogica SEO Redirection21/8/201917/6/2026
The seo-redirection plugin before 4.3 for WordPress has stored XSS.
ModificadaAlta (7.2)2.1%—Redirection26/6/201817/6/2026
Redirection version 2.7.1 contains a Serialisation vulnerability possibly allowing ACE vulnerability in Settings page AJAX that can result in could allow admin to execute arbitrary code in some circumstances. This attack appear to be exploitable via Attacker must have access to admin account. This vulnerability…
ModificadaAlta (7.2)2.0%—Redirection26/6/201817/6/2026
Redirection version 2.7.3 contains a ACE via file inclusion vulnerability in Pass-through mode that can result in allows admins to execute any PHP file in the filesystem. This attack appear to be exploitable via Attacker must be have access to an admin account on the target site. This vulnerability appears to have…
ModificadaMedia (6.8)1.0%—Redirection Project Redirection11/2/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Redirection Page plugin 1.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings or conduct cross-site scripting (XSS) attacks via the (2) source or (3) redir parameter in an…
ModificadaMedia (4.3)2.4%—John Godley Redirection Plugin28/11/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (1) view/admin/log_item.php and (2) view/admin/log_item_details.php in the Redirection plugin 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Referer HTTP header in a request to a post that does not exist.