Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Fivestarplugins Five Star Restaurant Menu20/11/202317/6/2026
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.
ModificadaAlta (8.8)0.27%—Pricelisto Best Restaurant Menu18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PriceListo Best Restaurant Menu by PriceListo.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.3.1.
ModificadaMedia (6.1)0.39%—Oracle Restaurant Menu - Food Ordering System - Table Reservation24/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GloriaFood Restaurant Menu – Food Ordering System – Table Reservation plugin <= 2.3.6 versions.
ModificadaMedia (6.1)0.41%—Fivestarplugins Five Star Restaurant Menu25/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions.
ModificadaAlta (8.8)0.26%—Fivestarplugins Five Star Restaurant Menu17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions.
ModificadaMedia (5.4)0.67%—Oracle Restaurant Menu - Food Ordering System - Table Reservation6/2/202317/6/2026
The Restaurant Menu WordPress plugin before 2.3.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.60%—Thingsforrestaurants Quick Restaurant Menu27/1/202317/6/2026
The Quick Restaurant Menu plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke those actions intended for…
ModificadaMedia (4.3)0.36%—Thingsforrestaurants Quick Restaurant Menu27/1/202317/6/2026
The Quick Restaurant Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to update menu items, via forged request granted they can…
ModificadaMedia (4.8)0.54%—Thingsforrestaurants Quick Restaurant Menu27/1/202317/6/2026
The Quick Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…
ModificadaMedia (4.3)0.65%—Thingsforrestaurants Quick Restaurant Menu27/1/202317/6/2026
The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the fact that during menu item deletion/modification, the plugin does not verify that the post ID provided to the AJAX action is indeed a menu item. This makes it…
ModificadaAlta (8.8)0.53%—Oracle Restaurant Menu - Food Ordering System - Table Reservation3/11/202217/6/2026
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as forms_action, set_option, & chosen_options…
ModificadaMedia (6.5)0.58%—Oracle Restaurant Menu - Food Ordering System - Table Reservation3/11/202217/6/2026
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal…
ModificadaMedia (4.8)0.64%—Motopress Restaurant Menu1/11/202117/6/2026
The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaCrítica (9.8)31%—Fivestarplugins Five Star Restaurant Menu11/3/202117/6/2026
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.
ModificadaMedia (6.1)0.93%—Easy PDF Restaurant Menu Upload Project Easy PDF Restaurant Menu Upload30/8/201917/6/2026
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.