Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
720 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.35% | — | Cryoutcreations Serious SliderAI | 16/8/2026 | 20/8/2026 | The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Baja (1.9) | 1.1% | — | Adolfosalasgomez3011 Slidev-builder-mcpAI | 8/8/2026 | 12/8/2026 | A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command injection. The attack is only possible with… | |
| Aplazada | Media (6.4) | 0.43% | — | MetasliderAI | 6/8/2026 | 12/8/2026 | The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.4) | 0.23% | — | Slick SliderAI | 6/8/2026 | 26/8/2026 | The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when a user views the affected post. | |
| Aplazada | Media (4.9) | 0.51% | — | Ljapps WP Tripadvisor Review SliderAI | 5/8/2026 | 12/8/2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.36% | — | WP Responsive Thumbnail SliderAI | 1/8/2026 | 12/8/2026 | The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id']… | |
| Aplazada | Media (4.3) | 0.14% | — | Ljapps WP Google Review SliderAI | 27/7/2026 | 27/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | Ljapps WP Google Review SliderAI | 27/7/2026 | 27/7/2026 | Administrator SQL Injection in WP Google Review Slider <= 18.4 versions. | |
| Aplazada | Media (4.3) | 0.27% | — | Product Slider FOR WoocommerceAI | 23/7/2026 | 23/7/2026 | Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Slider PROAI | 23/7/2026 | 23/7/2026 | Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions. | |
| Aplazada | Media (4.9) | 0.48% | — | Ljapps WP Tripadvisor Review SliderAI | 16/7/2026 | 16/7/2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, 14.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.23% | — | Ultimate Before After Image Slider AND GalleryAI | 14/7/2026 | 29/9/2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode content verbatim), allowing users with administrator-level… | |
| Aplazada | Media (4.3) | 0.41% | — | Nextendweb Smart Slider 3AI | 13/7/2026 | 14/7/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles and full content excerpts of private, draft,… | |
| Aplazada | Media (6.4) | 0.33% | — | Logoslider Logo SliderAI | 10/7/2026 | 10/7/2026 | The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lgx_tooltip_position' parameter in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.5) | 1.0% | — | Jssor SliderAI | 8/7/2026 | 8/7/2026 | The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.1.24 via the 'url' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. | |
| Aplazada | Alta (7.1) | 0.25% | — | Themepunch Slider RevolutionAI | 2/7/2026 | 2/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider Revolution: from 7.0.0 through 7.0.16. | |
| Aplazada | Alta (7.5) | 0.46% | — | WP Review Slider PROAI | 2/7/2026 | 2/7/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action in versions up to, and including, 12.7.2. The parameter is read via $_POST['notinstring'] and passed through sanitize_text_field() — which strips HTML and whitespace but… | |
| Aplazada | Media (6.1) | 0.37% | — | WP Google Places Review SliderAI | 1/7/2026 | 1/7/2026 | The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is… | |
| Aplazada | Alta (7.1) | 0.25% | — | Quick Interest SliderAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Masterslider Master SliderAI | 25/6/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider master-slider allows Reflected XSS.This issue affects Master Slider: from n/a through 3.11.3. | |
| Aplazada | Alta (7.5) | 0.43% | — | Shapedsmart Smart Post Show PROAIReal Testimonials PROAIProduct Slider FOR Woocommerce PROAI | 24/6/2026 | 25/6/2026 | Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for… | |
| Aplazada | Media (6.4) | 0.20% | — | Slideshow Gallery LiteAI | 18/6/2026 | 18/6/2026 | The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versions up to, and including, 1.8.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.1) | 0.82% | — | WP Review Slider PROAI | 16/6/2026 | 17/6/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function,… | |
| Aplazada | Alta (8.8) | 0.46% | — | WP Review Slider PROAI | 16/6/2026 | 17/6/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array… | |
| Aplazada | Alta (8.8) | 0.46% | — | WP Review Slider PROAI | 16/6/2026 | 17/6/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strings prior to json_decode(), which… |