Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.7) | 0.30% | — | Gtranslate | 19/5/2026 | 23/7/2026 | Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing. This issue affects Translate Drupal with GTranslate: from 0.0.0 before 3.0.5. | |
| Aplazada | Media (4.9) | 0.64% | — | Loco TranslateAI | 5/5/2026 | 17/6/2026 | The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via the `fsReference` AJAX route. This is due to the `findSourceFile()` method normalizing user-supplied `ref` paths containing `../` directory traversal sequences without validating that the resolved… | |
| Aplazada | Media (6.1) | 0.37% | — | Loco TranslateAI | 31/3/2026 | 17/6/2026 | The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (6.5) | 0.34% | — | Conveythis TranslateAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ConveyThis: from n/a through <= 269.9. | |
| Aplazada | Alta (8.1) | 0.37% | — | Cozmoslabs Translatepress-multilingualAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.10.2. | |
| Aplazada | Media (6.1) | 0.23% | — | Byaidu PdfmathtranslateAI | 30/10/2025 | 17/6/2026 | An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external websites via the file parameter to the /gradio_api endpoint. This vulnerability could be exploited for phishing attacks or to bypass security… | |
| Aplazada | Media (6.9) | 0.37% | — | Wikimedia Mediawiki Translate ExtensionAI | 21/10/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Translate Extension allows Footprinting. Translate extension appears to use jobs to make edits to translation pages. This causes the CheckUser tool to log the wrong IP and User-Agent making these edits… | |
| Aplazada | Alta (7.2) | 0.67% | — | Conveyothis TranslateAI | 22/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ConveyThis ConveyThis conveythis-translate allows Object Injection.This issue affects ConveyThis: from n/a through <= 269.1. | |
| Aplazada | Media (5.4) | 0.35% | — | Mythemeshop MY WP TranslateAI | 11/9/2025 | 17/6/2026 | The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtswpt_remove_plugin() and ajax_update_export_code() functions in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (8.8) | 0.31% | — | Mythemeshop MY WP TranslateAI | 11/9/2025 | 30/9/2026 | The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_import_strings() function in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.5) | 0.17% | — | Reubenthiessen Translate This Gtranslate ShortcodeAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reubenthiessen Translate This gTranslate Shortcode translate-this-google-translate-web-element-shortcode allows Stored XSS.This issue affects Translate This gTranslate Shortcode: from n/a through <= 1.0. | |
| Aplazada | Media (6.4) | 0.24% | — | Translate This Gtranslate ShortcodeAI | 16/8/2025 | 17/6/2026 | The Translate This gTranslate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘base_lang’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (7.5) | 9.5% | — | Translated Lara MCPAI | 21/7/2025 | 17/6/2026 | Lara Translate MCP Server is a Model Context Protocol (MCP) Server for Lara Translate API. Versions 0.0.11 and below contain a command injection vulnerability which exists in the @translated/lara-mcp MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to child_process.exec,… | |
| Aplazada | Alta (7.2) | 0.79% | — | Cozmoslabs TranslatepressAI | 27/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.9.6. | |
| Aplazada | Alta (7.1) | 0.15% | — | Blackbam Tinymce Advanced Qtranslate FIX Editor ProblemsAI | 13/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blackbam TinyMCE Advanced qTranslate fix editor problems tinymce-advanced-qtranslate-fix-editor-problems allows Stored XSS.This issue affects TinyMCE Advanced qTranslate fix editor problems: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.3) | 0.18% | — | Loco TranslateAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tim W Loco Translate loco-translate allows Cross Site Request Forgery.This issue affects Loco Translate: from n/a through <= 2.6.9. | |
| Aplazada | Media (5.3) | 0.54% | — | Gtranslate Google Language TranslatorAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in edo888 Google Language Translator google-language-translator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Language Translator: from n/a through <= 6.0.19. | |
| Aplazada | Media (4.3) | 0.40% | — | Onthegosystems Qtranslate X CleanupAIOnthegosystems Wpml ImportAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in OntheGoSystems qTranslate X Cleanup and WPML Import allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects qTranslate X Cleanup and WPML Import: from n/a through 3.0.1. | |
| Aplazada | Media (5.3) | 0.42% | — | Language Translate Widget FOR Wordpress ConveyethisAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in ConveyThis Translate Team Language Translate Widget for WordPress – ConveyThis allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Language Translate Widget for WordPress – ConveyThis: from n/a through 234. | |
| Aplazada | Media (6.1) | 0.16% | — | Wpglobus Translate OptionsAI | 31/10/2024 | 17/6/2026 | The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the on__translate_options_page() function. This makes it possible for unauthenticated attackers to inject malicious web… | |
| Analizada | Media (5.4) | 0.51% | — | Gtranslate Google Language Translator | 16/10/2024 | 17/6/2026 | The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (5.4) | 0.39% | — | Hahncreativegroup WP TranslateAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in HahnCreativeGroup WP Translate.This issue affects WP Translate: from n/a through 5.3.0. | |
| Aplazada | Media (4.4) | 0.27% | — | Automatic Translator With Google TranslateAI | 22/5/2024 | 17/6/2026 | The Automatic Translator with Google Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom font setting in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.25% | — | Cozmoslabs TranslatepressAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban TranslatePress.This issue affects TranslatePress: from n/a through 2.7.5. | |
| Aplazada | Media (6.1) | 0.46% | — | Angular-translateAI | 26/4/2024 | 17/6/2026 | angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks. |