Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.19% | — | Wow-company Sticky ButtonsAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Sticky Buttons sticky-buttons allows Cross Site Request Forgery.This issue affects Sticky Buttons: from n/a through <= 4.1.1. | |
| Aplazada | Alta (7.1) | 0.23% | — | Asif Shakeel Sticky ButtonAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asif Shakeel Sticky Button sticky-chat-button allows Stored XSS.This issue affects Sticky Button: from n/a through <= 1.0. | |
| Aplazada | Media (5.3) | 0.50% | — | Premio MY Sticky ElementsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Premio My Sticky Elements mystickyelements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Sticky Elements: from n/a through <= 2.1.3. | |
| Analizada | Media (4.8) | 0.31% | — | Sanil Sticky Social Icons | 6/12/2024 | 17/6/2026 | The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.9) | 0.29% | — | Sanil Sticky Social IconsAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sanil Shakya Sticky Social Icons sticky-social-icons allows Stored XSS.This issue affects Sticky Social Icons: from n/a through <= 1.2.1. | |
| Aplazada | Alta (7.5) | 0.94% | — | MP3 Sticky PlayerAI | 23/11/2024 | 17/6/2026 | The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Please note… | |
| Aplazada | Media (6.4) | 1.1% | — | Lazy Load Videos AND Sticky ControlAI | 21/11/2024 | 17/6/2026 | The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lazy-load-videos-and-sticky-control' shortcode in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Alta (7.1) | 0.20% | — | MD Eftakhairul Islam Sticky Social BARAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Md Eftakhairul Islam Sticky Social Bar sticky-social-bar allows Cross Site Request Forgery.This issue affects Sticky Social Bar: from n/a through <= 2.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Buooy Sticky HeaderAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Buooy Buooy Sticky Header buooy-sticky-header allows Reflected XSS.This issue affects Buooy Sticky Header: from n/a through <= 0.5.2. | |
| Analizada | Media (4.8) | 0.44% | — | Premio MY Sticky BAR | 13/9/2024 | 17/6/2026 | The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.3 does not validate and escape some of its settings before outputting them back in the page, which could allow users with a high role to perform Stored Cross-Site Scripting attacks. | |
| Analizada | Media (4.8) | 0.46% | — | Premio MY Sticky BAR | 1/8/2024 | 17/6/2026 | The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Analizada | Media (6.1) | 0.36% | — | A17lab Wpstickybar | 30/7/2024 | 17/6/2026 | The WpStickyBar WordPress plugin through 2.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Crítica (9.8) | 27% | 💥 Exploit | A17lab Wpstickybar | 30/7/2024 | 17/6/2026 | The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | |
| Aplazada | Media (5.4) | 0.36% | — | Hardik Chavada Sticky Social Media IconsAI | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1. | |
| Aplazada | Media (5.9) | 0.44% | — | Hidden Depth Sticky BannerAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Sticky banner allows Stored XSS.This issue affects Sticky banner: from n/a through 1.2.0. | |
| Aplazada | Media (5.9) | 0.28% | — | Habibur Rahman Sticky Social LinkAI | 8/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Habibur Rahman Sticky Social Link sticky-social-link allows DOM-Based XSS.This issue affects Sticky Social Link: from n/a through <= 2.0.1. | |
| Analizada | Alta (7.5) | 0.28% | — | Wow-company Sticky Buttons | 2/5/2024 | 17/6/2026 | The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks | |
| Aplazada | Alta (7.1) | 0.18% | — | Toast Plugins Sticky AnythingAI | 29/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Sticky Anything allows Cross-Site Scripting (XSS).This issue affects Sticky Anything: from n/a through 2.1.5. | |
| Aplazada | Alta (7.1) | 0.33% | — | Toast Plugins Sticky AnythingAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toast Plugins Sticky Anything.This issue affects Sticky Anything: from n/a through 2.1.5. | |
| Analizada | Media (6.1) | 0.32% | — | Smartcalc Osticky | 15/2/2024 | 17/6/2026 | An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a popular Support ticket system. The Open Redirect vulnerability allows attackers to control the return parameter in the URL to a… | |
| Modificada | Media (4.8) | 0.30% | — | Wow-company Sticky Buttons | 23/1/2024 | 17/6/2026 | The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sticky URLs in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Modificada | Media (4.3) | 0.21% | — | Premio MY Sticky BAR | 11/1/2024 | 17/6/2026 | The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.6. This is due to missing or incorrect nonce validation in mystickymenu-contact-leads.php. This makes it possible for unauthenticated attackers to trigger the export of a CSV file containing… | |
| Modificada | Media (4.8) | 0.34% | — | Gingerplugins Sticky Chat Widget | 29/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ginger Plugins Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button allows Stored XSS.This issue affects Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call… | |
| Modificada | Media (6.5) | 0.34% | 💥 PoC | Remyandrade Sticky Notes APP | 22/11/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in Sourcecodester Sticky Notes App Using PHP with Source Code v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to add-note.php. | |
| Modificada | Media (5.4) | 0.52% | — | Premio Mystickymenu | 20/11/2023 | 17/6/2026 | The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in user to perform the actions. |