Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.39% | — | Ashish Ajani WP Simple Html SitemapAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani WP Simple HTML Sitemap allows Reflected XSS.This issue affects WP Simple HTML Sitemap: from n/a through 2.8. | |
| Modificada | Alta (7.5) | 0.67% | — | Lineagrafica Multilingual AND Multistore Sitemap PRO | 7/2/2024 | 17/6/2026 | Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before version 1.6.6, a guest can download personal information without restriction. | |
| Modificada | Alta (8.8) | 0.31% | — | Webbjocke Simple WP Sitemap | 17/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Webbjocke Simple Wp Sitemap.This issue affects Simple Wp Sitemap: from n/a through 1.2.1. | |
| Modificada | Alta (8.8) | 0.32% | — | Webternsolutions Video XML Sitemap Generator | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tradebooster Video XML Sitemap Generator.This issue affects Video XML Sitemap Generator: from n/a through 1.0.0. | |
| Modificada | Alta (8.8) | 0.30% | — | Wpgrim Dynamic XML Sitemaps Generator FOR Google | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPGrim Dynamic XML Sitemaps Generator for Google plugin <= 1.3.3 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Digitalinspiration Google XML Sitemap FOR Images | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Images plugin <= 2.1.3 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Freelancer-coder Wordpress Simple Html Sitemap | 8/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions. | |
| Modificada | Alta (7.2) | 0.68% | — | Click5interactive Sitemap BY Click5 | 6/11/2023 | 17/6/2026 | The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it. | |
| Modificada | Media (5.4) | 0.31% | — | Freelancer-coder Wordpress Simple Html Sitemap | 18/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions. | |
| Modificada | Alta (8.8) | 0.32% | — | Digitalinspiration Google XML Sitemap FOR Mobile | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions. | |
| Modificada | Media (6.1) | 1.00% | 💥 Exploit | Codeermeneer Companion Sitemap Generator | 10/7/2023 | 17/6/2026 | The Companion Sitemap Generator WordPress plugin before 4.5.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Alta (8.8) | 0.26% | — | Digitalinspiration Google XML Sitemap FOR Videos | 15/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions. | |
| Modificada | Media (4.8) | 0.40% | — | Sitemap Index Project Sitemap Index | 23/4/2023 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Twardes Sitemap Index plugin <= 1.2.3 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Codeermeneer Companion Sitemap Generator | 13/3/2023 | 17/6/2026 | The Companion Sitemap Generator WordPress plugin through 4.5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.52% | — | Simple Sitemap Project Simple Sitemap | 30/1/2023 | 17/6/2026 | The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.4) | 0.47% | — | Sitemap Project Sitemap | 23/1/2023 | 17/6/2026 | The Sitemap WordPress plugin before 4.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Media (4.8) | 0.54% | — | Kwayyinfotech Kwayy Html Sitemap | 26/12/2022 | 17/6/2026 | The Kwayy HTML Sitemap WordPress plugin before 4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.59% | — | Google XML Sitemaps Project Google XML Sitemaps | 20/6/2022 | 17/6/2026 | The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Xmlsitemapgenerator XML Sitemap Generator | 23/5/2022 | 17/6/2026 | The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on. | |
| Modificada | Media (6.1) | 0.80% | — | Advanced Image Sitemap Project Advanced Image Sitemap | 16/5/2022 | 17/6/2026 | The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting. | |
| Modificada | Media (5.4) | 0.57% | — | Google-news-sitemap Project Google-news-sitemap | 6/5/2022 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role. | |
| Modificada | Alta (8.8) | 11% | 💥 Exploit | Sitemap Project Sitemap | 2/5/2022 | 17/6/2026 | The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register… | |
| Modificada | Media (6.1) | 1.5% | — | Bwp-google-xml-sitemaps Project Bwp-google-xml-sitemaps | 14/3/2022 | 17/6/2026 | The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins | |
| Modificada | Alta (8.8) | 0.52% | — | Xml-sitemaps Unlimited Sitemap Generator | 24/11/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specially crafted web page. | |
| Modificada | Media (4.8) | 0.64% | — | WP Sitemap Page Project WP Sitemap Page | 1/11/2021 | 17/6/2026 | The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. |