Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

61 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.39%—Ashish Ajani WP Simple Html SitemapAI18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani WP Simple HTML Sitemap allows Reflected XSS.This issue affects WP Simple HTML Sitemap: from n/a through 2.8.
ModificadaAlta (7.5)0.67%—Lineagrafica Multilingual AND Multistore Sitemap PRO7/2/202417/6/2026
Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before version 1.6.6, a guest can download personal information without restriction.
ModificadaAlta (8.8)0.31%—Webbjocke Simple WP Sitemap17/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Webbjocke Simple Wp Sitemap.This issue affects Simple Wp Sitemap: from n/a through 1.2.1.
ModificadaAlta (8.8)0.32%—Webternsolutions Video XML Sitemap Generator18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tradebooster Video XML Sitemap Generator.This issue affects Video XML Sitemap Generator: from n/a through 1.0.0.
ModificadaAlta (8.8)0.30%—Wpgrim Dynamic XML Sitemaps Generator FOR Google13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPGrim Dynamic XML Sitemaps Generator for Google plugin <= 1.3.3 versions.
ModificadaAlta (8.8)0.31%—Digitalinspiration Google XML Sitemap FOR Images12/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Images plugin <= 2.1.3 versions.
ModificadaMedia (6.1)0.41%—Freelancer-coder Wordpress Simple Html Sitemap8/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions.
ModificadaAlta (7.2)0.68%—Click5interactive Sitemap BY Click56/11/202317/6/2026
The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.
ModificadaMedia (5.4)0.31%—Freelancer-coder Wordpress Simple Html Sitemap18/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions.
ModificadaAlta (8.8)0.32%—Digitalinspiration Google XML Sitemap FOR Mobile10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions.
ModificadaMedia (6.1)1.00%💥 ExploitCodeermeneer Companion Sitemap Generator10/7/202317/6/2026
The Companion Sitemap Generator WordPress plugin before 4.5.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaAlta (8.8)0.26%—Digitalinspiration Google XML Sitemap FOR Videos15/6/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions.
ModificadaMedia (4.8)0.40%—Sitemap Index Project Sitemap Index23/4/202317/6/2026
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Twardes Sitemap Index plugin <= 1.2.3 versions.
ModificadaMedia (5.4)0.44%—Codeermeneer Companion Sitemap Generator13/3/202317/6/2026
The Companion Sitemap Generator WordPress plugin through 4.5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.52%—Simple Sitemap Project Simple Sitemap30/1/202317/6/2026
The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as…
ModificadaMedia (5.4)0.47%—Sitemap Project Sitemap23/1/202317/6/2026
The Sitemap WordPress plugin before 4.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaMedia (4.8)0.54%—Kwayyinfotech Kwayy Html Sitemap26/12/202217/6/2026
The Kwayy HTML Sitemap WordPress plugin before 4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (4.8)0.59%—Google XML Sitemaps Project Google XML Sitemaps20/6/202217/6/2026
The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.1)2.1%💥 ExploitXmlsitemapgenerator XML Sitemap Generator23/5/202217/6/2026
The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.
ModificadaMedia (6.1)0.80%—Advanced Image Sitemap Project Advanced Image Sitemap16/5/202217/6/2026
The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.
ModificadaMedia (5.4)0.57%—Google-news-sitemap Project Google-news-sitemap6/5/202217/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role.
ModificadaAlta (8.8)11%💥 ExploitSitemap Project Sitemap2/5/202217/6/2026
The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register…
ModificadaMedia (6.1)1.5%—Bwp-google-xml-sitemaps Project Bwp-google-xml-sitemaps14/3/202217/6/2026
The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins
ModificadaAlta (8.8)0.52%—Xml-sitemaps Unlimited Sitemap Generator24/11/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specially crafted web page.
ModificadaMedia (4.8)0.64%—WP Sitemap Page Project WP Sitemap Page1/11/202117/6/2026
The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Orbitaley — Vulnerabilidades