Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.45% | — | Schema AND Structured Data FOR WP AND AMPAI | 10/6/2026 | 23/7/2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by… | |
| Analizada | Baja (2.1) | 0.18% | — | Opentelemetry Telemetry Schema Files | 4/6/2026 | 22/7/2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1.0` and `go.opentelemetry.io/otel/schema/v1.1` leaks one file descriptor on each successful `ParseFile` call. `ParseFile` opens the schema file and passes it to `Parse` without closing it; repeated… | |
| Aplazada | Media (4.9) | 0.29% | — | Wpsemplugins WP SEO Structured Data SchemaAI | 12/5/2026 | 17/6/2026 | The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ative_tab` parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Pendiente de análisis | Media (6.5) | 0.69% | — | Mafintosh Protocol-buffers-schemaAI | 15/4/2026 | 17/6/2026 | JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution. | |
| Analizada | Alta (7.4) | 0.29% | — | Schemahero | 30/3/2026 | 17/6/2026 | SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the mysqlColumnAsInsert function in file plugins/mysql/lib/column.go. | |
| Analizada | Alta (7.4) | 0.29% | — | Schemahero | 30/3/2026 | 17/6/2026 | SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the columnAsInsert function in file plugins/postgres/lib/column.go. | |
| Aplazada | Media (6.5) | 0.27% | — | Radiustheme Review SchemaAI | 25/3/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme Review Schema review-schema allows Retrieve Embedded Sensitive Data.This issue affects Review Schema: from n/a through <= 2.2.6. | |
| Aplazada | Media (6.4) | 0.16% | — | Schema ShortcodeAI | 21/3/2026 | 17/6/2026 | The Schema Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `itemscope` shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.27% | — | Schema AND Structured Data FOR WP AND AMPAI | 23/1/2026 | 17/6/2026 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saswp_custom_schema_field' profile field in all versions up to, and including, 1.54 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.23% | — | Schema Structured Data FOR WP AMPAI | 1/11/2025 | 17/6/2026 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all versions up to, and including, 1.51 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.24% | — | Schema ScalpelAI | 1/11/2025 | 17/6/2026 | The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping when outputting user-supplied data into JSON-LD schema markup. This makes it possible for authenticated… | |
| Aplazada | Media (6.3) | 0.26% | — | Schema Plugin FOR DiviAI | 3/10/2025 | 17/6/2026 | The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all versions up to, and including, 4.3.2 via deserialization of untrusted input via the wpt_schema_breadcrumbs shortcode. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (6.1) | 0.21% | — | Schema AND Structured Data FOR WP AND AMPAI | 1/10/2025 | 17/6/2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modifications, making it possible for unauthenticated attackers to conduct Stored XSS attacks via post comments. | |
| Analizada | Media (6.5) | 0.32% | — | Open-federation Json-schema-editor-visual | 24/9/2025 | 17/6/2026 | json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers to inject or delete properties on Object.prototype via supplying a crafted payload, causing denial of… | |
| Analizada | Media (5.4) | 0.28% | — | Wpsemplugins WP SEO Structured Data Schema | 8/5/2025 | 17/6/2026 | The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Price Range’ parameter in all versions up to, and including, 2.7.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (4.8) | 0.21% | — | Joelittlejohn Jsonschema2pojoAI | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in joelittlejohn jsonschema2pojo 1.2.2. This issue affects the function apply of the file org/jsonschema2pojo/rules/SchemaRule.java of the component JSON File Handler. The manipulation leads to stack-based buffer overflow. Attacking locally is a… | |
| Aplazada | Alta (8.8) | 0.66% | — | Radiustheme Review SchemaAI | 11/3/2025 | 17/6/2026 | The Review Schema plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.4 via post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any… | |
| Aplazada | Media (6.4) | 0.33% | — | Youtube Playlists With SchemaAI | 19/2/2025 | 17/6/2026 | The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt_grid' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.16% | — | Mythemeshop Schema LiteAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop Schema Lite allows Cross Site Request Forgery.This issue affects Schema Lite: from n/a through 1.2.2. | |
| Modificada | Media (5.3) | 0.44% | — | Schemaapp Schema APP Structured Data | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in vberkel Schema App Structured Data schema-app-structured-data-for-schemaorg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through <= 1.23.1. | |
| Aplazada | Media (6.1) | 0.53% | — | Schemaapp Schema APP Structured DataAI | 12/12/2024 | 17/6/2026 | The Schema App Structured Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.5) | 0.29% | — | Sergiomico SimpleschemaAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sergiomico SimpleSchema simpleschema-free allows DOM-Based XSS.This issue affects SimpleSchema: from n/a through <= 1.7.6.9. | |
| Aplazada | Alta (7.1) | 0.14% | — | Check JsonschemaAI | 29/11/2024 | 17/6/2026 | check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the basename of a remote schema as the name of the file in the cache, e.g. `https://example.org/schema.json` will be stored as `schema.json`. This naming allows for conflicts. If an attacker can get a user… | |
| Aplazada | Media (5.3) | 0.34% | — | Magazine3 Schema AND Structured Data FOR WP AND AMPAI | 24/10/2024 | 17/6/2026 | Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Schema & Structured Data for WP & AMP: from n/a through <= 1.3.5. | |
| Modificada | Media (5.4) | 0.39% | — | Magazine3 Schema & Structured Data FOR WP & AMP | 17/7/2024 | 17/6/2026 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within the Q&A Block widget in all versions up to, and including, 1.33 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… |