Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
721 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Social Login AND RegisterAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Social Media AND Share IconsAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | |
| Aplazada | Crítica (9.8) | 0.63% | — | Soclever Social Login Sharing Buttons With AnalyticsAI | 22/8/2026 | 26/8/2026 | The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators.… | |
| Aplazada | Crítica (9.8) | 0.50% | — | WP Social Media LoginAI | 22/8/2026 | 26/8/2026 | The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address. | |
| Aplazada | Alta (7.1) | 0.25% | — | Nextscripts Social Networks Auto PosterAI | 19/8/2026 | 26/8/2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Social Login AND RegisterAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Smashballoon Social Post FeedAI | 16/8/2026 | 20/8/2026 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Shortcode Attribute in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.2) | 0.76% | — | Laravel SocialiteAI | 14/8/2026 | 24/9/2026 | Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function within FacebookProvider.php. Attackers who obtain a valid, unexpired… | |
| Aplazada | Media (6.5) | 0.33% | — | WP Social AvatarAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. | |
| Aplazada | Alta (8.1) | 0.75% | — | Ventraconnect Social Login Passwordless LoginAI | 12/8/2026 | 12/8/2026 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me… | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | SAP Social IntelligenceAI | 11/8/2026 | 26/8/2026 | Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Language) string into the underlying database without further authorization. Successful exploitation could allow the attacker to make malicious changes to the database… | |
| Aplazada | Alta (7.1) | 0.25% | — | Heateor Super SocializerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | |
| Aplazada | Alta (8.8) | 0.50% | — | Heateor Super SocializerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. | |
| Aplazada | Media (4.7) | 0.39% | — | Smashballoon Social Photo FeedAI | 5/8/2026 | 12/8/2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query String in all versions up to, and including, 6.11.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.5) | 0.55% | — | Login-socialAI | 2/8/2026 | 26/8/2026 | The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account,… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Wpwebelite Woocommerce Social LoginAI | 2/8/2026 | 12/8/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or… | |
| Aplazada | Alta (8.1) | 0.38% | — | Miniorange Social Login AND RegisterAI | 29/7/2026 | 30/7/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any… | |
| Aplazada | Media (6.5) | 0.22% | — | Wordpress Social Login AND RegisterAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Wpsocialninja WP Social NinjaAI | 23/7/2026 | 23/7/2026 | Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions. | |
| Aplazada | Alta (8.1) | 0.38% | — | Social Login Passkeys Magic Link Email OTPAI | 20/7/2026 | 21/7/2026 | The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email… | |
| Aplazada | Crítica (9.6) | 0.25% | — | Word Count AND Social SharesAI | 14/7/2026 | 14/7/2026 | The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g.… | |
| Aplazada | Crítica (9.8) | 0.89% | — | Miniorange Social Login AND RegisterAI | 10/7/2026 | 13/7/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_field' POST… | |
| Aplazada | Media (4.7) | 0.15% | — | Smashballoon Social Photo FeedAI | 8/7/2026 | 8/7/2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (6.1) | 0.36% | — | Heateor Super SocializerAI | 8/7/2026 | 8/7/2026 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and including, 7.14.5 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Alta (8.1) | 0.19% | — | Heateor Social LoginAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions. |