Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (8.1) | 0.46% | — | Simple-gitAI | 29/9/2026 | 30/9/2026 | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path… | |
| Aplazada | Alta (8.8) | 0.25% | — | CmsimpleAI | 22/9/2026 | 25/9/2026 | CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentication is cookie-only and no CSRF token is enforced, an unauthenticated attacker… | |
| Aplazada | Media (5.3) | 0.42% | — | Really-simple-plugins Really Simple SecurityAI | 18/9/2026 | 18/9/2026 | The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages. | |
| Aplazada | Media (5.3) | 0.29% | — | Simple-membership-plugin Simple MembershipAI | 17/9/2026 | 17/9/2026 | Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. | |
| Aplazada | Baja (2.3) | 0.36% | — | Really-simple-plugins Really Simple SecurityAI | 14/9/2026 | 19/9/2026 | Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a… | |
| Aplazada | Alta (7.5) | 0.34% | — | Really-simple-plugins Really Simple SecurityAI | 13/9/2026 | 14/9/2026 | The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. | |
| Aplazada | Media (5.4) | 0.23% | — | Simple-membership-plugin Simple MembershipAI | 13/9/2026 | 14/9/2026 | The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level. | |
| Aplazada | Media (6.5) | 0.22% | — | Idokd Simple PaymentAI | 11/9/2026 | 11/9/2026 | Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Getsimple CMSAIGetsimple CMS CEAI | 11/9/2026 | 30/9/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security… | |
| Aplazada | Media (6.5) | 0.31% | — | Simple Captcha With Cloudflare TurnstileAI | 11/9/2026 | 11/9/2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
| Aplazada | Alta (7.2) | 0.49% | — | Plugin-planet Simple Ajax ChatAI | 11/9/2026 | 11/9/2026 | The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (5.6) | 0.25% | — | Simple Cloudflare TurnstileAI | 10/9/2026 | 10/9/2026 | Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions. | |
| Aplazada | Alta (8.8) | 0.67% | — | CmsimpleAICmsimple CoauthorsAI | 8/9/2026 | 9/9/2026 | A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing crafted external or uploaded text content through the affected content import feature. | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 11/9/2026 | A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of… | |
| Aplazada | Media (5.5) | 0.76% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 8/9/2026 | A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.69% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be initiated remotely. The exploit is now… | |
| Aplazada | Alta (7.4) | 0.39% | — | Really Simple SSLAI | 3/9/2026 | 3/9/2026 | Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Idokd Simple PaymentAI | 3/9/2026 | 3/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions. | |
| Aplazada | Media (5.4) | 0.14% | — | Simple Membership Mailchimp IntegrationAI | 2/9/2026 | 3/9/2026 | The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is… | |
| Aplazada | Media (5.3) | 0.40% | — | Really Simple SSLAI | 2/9/2026 | 2/9/2026 | Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions. | |
| Aplazada | Alta (8.8) | 0.51% | — | Plugin-planet Simple Ajax ChatAI | 2/9/2026 | 3/9/2026 | The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators. | |
| Aplazada | Media (5.3) | 0.58% | — | Simple-membership-plugin Simple MembershipAI | 1/9/2026 | 1/9/2026 | The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is due to improper identity verification during the public registration flow in WordPress Multisite environments, where the plugin binds new Simple… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Simple Inventory SystemAI | 31/8/2026 | 1/9/2026 | A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an unknown part of the file /register.php of the component User Registration. Such manipulation of the argument last_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Simple Inventory SystemAI | 31/8/2026 | 31/8/2026 | A flaw has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file inventorymanagement.sql of the component Database Backup File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Media (6.6) | 0.43% | — | Really-simple-plugins Really Simple SecurityAI | 30/8/2026 | 31/8/2026 | The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbitrary code in the… |