Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.43% | — | Plainware Locatoraid Store LocatorAI | 7/1/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in plainware Locatoraid Store Locator locatoraid allows Object Injection.This issue affects Locatoraid Store Locator: from n/a through <= 3.9.50. | |
| Analizada | Media (5.4) | 0.31% | — | Wpexperts WP Multi Store Locator | 4/1/2025 | 17/6/2026 | The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web… | |
| Aplazada | Media (6.1) | 0.37% | — | G WEB PRO Store LocatorAI | 21/12/2024 | 17/6/2026 | The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Crítica (9.8) | 0.93% | — | Lotsoflocales Store LocatorAI | 20/12/2024 | 17/6/2026 | The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code… | |
| Analizada | Media (4.3) | 0.21% | — | Themify Store Locator | 13/12/2024 | 17/6/2026 | The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the setting_page() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged… | |
| Aplazada | Media (6.5) | 0.32% | — | Pierre Jego MAP Store LocatorAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Jégo Map Store Locator map-store-location allows DOM-Based XSS.This issue affects Map Store Locator: from n/a through <= 1.2.1. | |
| Aplazada | Media (6.1) | 0.39% | — | Locatoraid Store LocatorAI | 16/10/2024 | 17/6/2026 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all versions up to, and including, 3.9.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Alta (7.5) | 0.39% | — | Storelocatorplus Store Locator Plus | 26/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a through 2311.17.01. | |
| Aplazada | Media (6.8) | 0.62% | — | Agilelogix Store LocatorAI | 18/4/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AGILELOGIX Store Locator WordPress.This issue affects Store Locator WordPress: from n/a through 1.4.14. | |
| Aplazada | Media (5.9) | 0.36% | — | Plainware Locatoraid Store LocatorAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plainware Locatoraid Store Locator allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through 3.9.30. | |
| Modificada | Media (6.1) | 0.33% | — | Simplemap-plugin Simplemap Store Locator | 31/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Torbert SimpleMap Store Locator allows Reflected XSS.This issue affects SimpleMap Store Locator: from n/a through 2.6.1. | |
| Modificada | Media (6.1) | 0.69% | 💥 Exploit | Agilelogix Store Locator | 4/9/2023 | 17/6/2026 | The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.36% | — | Plainwaire Locatoraid Store Locator | 25/8/2023 | 17/6/2026 | Auth. (subscriber+) Stored Cross-Site Scripting') vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.18 versions. | |
| Modificada | Media (4.8) | 0.40% | — | Agilelogix Store Locator | 22/6/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in AGILELOGIX Store Locator WordPress plugin <= 1.4.9 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Wpexperts WP Multi Store Locator | 5/6/2023 | 17/6/2026 | The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.27% | — | Viadat Store Locator FOR Wordpress With Google Maps | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Agilelogix Store Locator | 23/1/2023 | 17/6/2026 | The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Media (6.1) | 0.25% | — | Agilelogix Store Locator | 18/11/2022 | 17/6/2026 | Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress. | |
| Modificada | Media (6.1) | 0.83% | — | De-baat Store Locator Plus | 17/5/2021 | 17/6/2026 | There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages. | |
| Modificada | Alta (8.8) | 1.1% | — | De-baat Store Locator Plus | 17/5/2021 | 17/6/2026 | There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin. | |
| Modificada | Crítica (9.8) | 3.0% | — | Store Locator Project Store Locator | 16/10/2017 | 17/6/2026 | SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php. | |
| Modificada | Media (6.5) | 1.0% | — | Store Locator Project Store Locator | 16/6/2015 | 17/6/2026 | SQL injection vulnerability in the Store Locator (locator) extension before 3.3.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. |