Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

721 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Wordpress Social Login AND RegisterAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
AplazadaAlta (7.1)0.25%—Social Media AND Share IconsAI24/8/202624/8/2026
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
AplazadaCrítica (9.8)0.63%—Soclever Social Login Sharing Buttons With AnalyticsAI22/8/202626/8/2026
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators.…
AplazadaCrítica (9.8)0.50%—WP Social Media LoginAI22/8/202626/8/2026
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.
AplazadaAlta (7.1)0.25%—Nextscripts Social Networks Auto PosterAI19/8/202626/8/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a…
AplazadaAlta (7.1)0.25%—Wordpress Social Login AND RegisterAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
AplazadaMedia (6.4)0.33%—Smashballoon Social Post FeedAI16/8/202620/8/2026
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Shortcode Attribute in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaCrítica (9.2)0.76%—Laravel SocialiteAI14/8/202624/9/2026
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function within FacebookProvider.php. Attackers who obtain a valid, unexpired…
AplazadaMedia (6.5)0.33%—WP Social AvatarAI13/8/202614/8/2026
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
AplazadaAlta (8.1)0.75%—Ventraconnect Social Login Passwordless LoginAI12/8/202612/8/2026
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me…
Pendiente de análisisMedia (6.3)0.27%—SAP Social IntelligenceAI11/8/202626/8/2026
Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Language) string into the underlying database without further authorization. Successful exploitation could allow the attacker to make malicious changes to the database…
AplazadaAlta (7.1)0.25%—Heateor Super SocializerAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
AplazadaAlta (8.8)0.50%—Heateor Super SocializerAI6/8/202612/8/2026
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
AplazadaMedia (4.7)0.39%—Smashballoon Social Photo FeedAI5/8/202612/8/2026
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query String in all versions up to, and including, 6.11.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
AplazadaAlta (7.5)0.55%—Login-socialAI2/8/202626/8/2026
The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account,…
AplazadaCrítica (9.8)0.70%—Wpwebelite Woocommerce Social LoginAI2/8/202612/8/2026
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or…
AplazadaAlta (8.1)0.38%—Miniorange Social Login AND RegisterAI29/7/202630/7/2026
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any…
AplazadaMedia (6.5)0.22%—Wordpress Social Login AND RegisterAI27/7/202627/7/2026
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
AplazadaMedia (5.3)0.33%—Wpsocialninja WP Social NinjaAI23/7/202623/7/2026
Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
AplazadaAlta (8.1)0.38%—Social Login Passkeys Magic Link Email OTPAI20/7/202621/7/2026
The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email…
AplazadaCrítica (9.6)0.25%—Word Count AND Social SharesAI14/7/202614/7/2026
The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g.…
AplazadaCrítica (9.8)0.89%—Miniorange Social Login AND RegisterAI10/7/202613/7/2026
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_field' POST…
AplazadaMedia (4.7)0.15%—Smashballoon Social Photo FeedAI8/7/20268/7/2026
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers…
AplazadaMedia (6.1)0.36%—Heateor Super SocializerAI8/7/20268/7/2026
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and including, 7.14.5 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaAlta (8.1)0.19%—Heateor Social LoginAI2/7/20262/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
Orbitaley — Vulnerabilidades