Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
157 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | JetreviewsAI | 2/7/2026 | 2/7/2026 | Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Geminilabs Site ReviewsAI | 26/6/2026 | 26/6/2026 | Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Cusrev Customer Reviews FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. | |
| Aplazada | Media (4.3) | 0.42% | — | Reviews AND Rating DocplannerAI | 24/6/2026 | 25/6/2026 | The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Media (5.3) | 0.47% | — | Helpfulcrowd Product ReviewsAI | 9/6/2026 | 23/7/2026 | The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1.2.9. This is due to the `helpfulcrowd_validate_token()` function using a loose comparison operator (`!=`) instead of a strict comparison (`!==`) when validating the… | |
| Aplazada | Media (6.1) | 0.29% | — | Cusrev Customer Reviews FOR WoocommerceAI | 16/4/2026 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.57% | — | Cusrev Customer Reviews FOR WoocommerceAI | 10/4/2026 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta value using strict… | |
| Aplazada | Media (5.9) | 0.24% | — | Richplugins Rich Showcase FOR Google ReviewsAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins Rich Showcase for Google Reviews widget-google-reviews allows Stored XSS.This issue affects Rich Showcase for Google Reviews: from n/a through <= 6.9.4.3. | |
| Aplazada | Media (4.8) | 0.41% | — | Dato CMSAIDato WEB PreviewsAI | 27/2/2026 | 17/6/2026 | Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated user to circumvent the restriction enforced on the configured frontend URL, enabling the loading of arbitrary external resources or origins. This issue affects Web Previews < v1.0.31. | |
| Aplazada | Media (5.3) | 0.34% | — | Villatheme Woocommerce Photo ReviewsAI | 26/2/2026 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews allows Code Injection.This issue affects WooCommerce Photo Reviews: from n/a through <= 1.4.4. | |
| Aplazada | Media (5.4) | 0.29% | — | BBR Plugins Better Business ReviewsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1. | |
| Aplazada | Alta (7.2) | 0.27% | — | Gowebsolutions WP Customer ReviewsAI | 19/2/2026 | 17/6/2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.2) | 0.27% | — | Cusrev Customer Reviews FOR WoocommerceAI | 12/2/2026 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and including, 5.97.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (if 'Enable for Guests'… | |
| Aplazada | Media (5.3) | 0.24% | — | Rustaurius Ultimate ReviewsAI | 23/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Reviews: from n/a through <= 3.2.16. | |
| Aplazada | Media (5.3) | 0.31% | — | Ryviu Product Reviews FOR WoocommerceAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Ryviu Ryviu – Product Reviews for WooCommerce ryviu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ryviu – Product Reviews for WooCommerce: from n/a through <= 3.1.26. | |
| Aplazada | Alta (7.1) | 0.26% | — | Cridiostudio Listingpro ReviewsAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro Reviews listingpro-reviews allows Reflected XSS.This issue affects ListingPro Reviews: from n/a through < 2.9.11. | |
| Aplazada | Media (6.4) | 0.22% | — | Nearby NOW ReviewsAI | 9/1/2026 | 17/6/2026 | The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter of the nn-tech shortcode in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.27% | — | Cusrev Customer Reviews FOR WoocommerceAI | 7/1/2026 | 7/10/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with customer-level access… | |
| Aplazada | Media (4.3) | 0.18% | — | BBR Plugins Better Business ReviewsAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1. | |
| Aplazada | Media (5.3) | 0.21% | — | Woo-reviews-by-wiremoAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Wiremo Wiremo woo-reviews-by-wiremo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wiremo: from n/a through <= 1.4.99. | |
| Aplazada | Media (6.4) | 0.35% | — | Reviews SortedAI | 12/12/2025 | 17/6/2026 | The Reviews Sorted plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'space' parameter of the [reviews-slider] shortcode in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.23% | — | Trustindex Widgets FOR Google ReviewsAI | 11/12/2025 | 30/9/2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `trustindex` shortcode in all versions up to, and including, 13.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (7.2) | 0.37% | — | Social Reviews AND RecommendationsAI | 9/12/2025 | 30/9/2026 | The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in the 'trim_text' function in all versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (7.2) | 0.38% | — | Rich Shortcodes FOR Google ReviewsAI | 6/12/2025 | 17/6/2026 | The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contents of a Google Review in all versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.2) | 0.40% | — | Widgets FOR Google ReviewsAI | 6/12/2025 | 17/6/2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 13.2.4 due to insufficient input sanitization and output escaping on Google Reviews data imported by the plugin. This makes it possible for unauthenticated attackers to inject… |