Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.38% | — | Lfprojects MCP Typescript SDK | 4/2/2026 | 15/7/2026 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport… | |
| Analizada | Media (4.8) | 0.23% | — | Typesettercms Typesetter | 14/1/2026 | 14/7/2026 | Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status move message handling. The path parameter is reflected into the HTML output without proper output encoding in include/admin/Tools/Status.php. An… | |
| Analizada | Media (4.8) | 0.23% | — | Typesettercms Typesetter | 14/1/2026 | 14/7/2026 | Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status functionality. The path parameter is reflected into the HTML response without proper output encoding in include/admin/Tools/Status.php. An authenticated… | |
| Analizada | Media (4.8) | 0.23% | — | Typesettercms Typesetter | 14/1/2026 | 14/7/2026 | Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Editing component. The images parameter (submitted as images[] in a POST request) is reflected into an HTML href attribute without proper context-aware output encoding in include/tool/Editing.php. An… | |
| Aplazada | Alta (8.8) | 0.72% | — | Buddypress Xprofile Custom Field TypesAI | 6/1/2026 | 30/9/2026 | The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_field' function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Analizada | Alta (8.7) | 0.44% | — | Lfprojects MCP Typescript SDK | 5/1/2026 | 14/7/2026 | Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression used during URI matching contains nested quantifiers that can… | |
| Analizada | Alta (7.6) | 0.51% | — | Lfprojects MCP Typescript SDK | 2/12/2025 | 17/6/2026 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with… | |
| Aplazada | Alta (8.6) | 0.29% | — | Pebas Couponxxl Custom Post TypesAI | 27/6/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in pebas CouponXxL Custom Post Types couponxxl-cpt allows Privilege Escalation.This issue affects CouponXxL Custom Post Types: from n/a through <= 3.0. | |
| Aplazada | Media (6.5) | 0.25% | — | Codemanas Search With TypesenseAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeManas Search with Typesense search-with-typesense allows Stored XSS.This issue affects Search with Typesense: from n/a through <= 2.0.10. | |
| Analizada | Media (4.8) | 0.31% | — | Deluxeblogtips MB Custom Post Types & Custom Taxonomies | 15/5/2025 | 17/6/2026 | The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (7.1) | 0.15% | — | Ldrumm Unsafe-mimetypesAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ldrumm Unsafe Mimetypes unsafe-mimetypes allows Stored XSS.This issue affects Unsafe Mimetypes: from n/a through <= 0.1.4. | |
| Aplazada | Media (4.3) | 0.21% | — | Labinator Content Types DuplicatorAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Labinator Labinator Content Types Duplicator labinator-content-types-duplicator allows Cross Site Request Forgery.This issue affects Labinator Content Types Duplicator: from n/a through <= 1.1.3. | |
| Modificada | Media (4.9) | 0.56% | — | Codemanas Search With Typesense | 25/2/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in CodeManas Search with Typesense search-with-typesense allows Path Traversal.This issue affects Search with Typesense: from n/a through <= 2.0.8. | |
| Aplazada | Media (6.5) | 0.28% | — | Setmore Theme Custom Post TypesAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Setmore SetMore Theme – Custom Post Types service-provider-profile-cpt allows Stored XSS.This issue affects SetMore Theme – Custom Post Types: from n/a through <= 1.1. | |
| Aplazada | Media (5.3) | 0.39% | — | Xserver Typesquare WebfontsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in XSERVER Inc. TypeSquare Webfonts allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects TypeSquare Webfonts: from n/a through 2.0.7. | |
| Aplazada | Media (6.4) | 0.38% | — | Wpforms File Upload TypesAI | 25/10/2024 | 17/6/2026 | The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Analizada | Media (5.4) | 0.34% | — | Newsignature WP Easy Post Types | 18/10/2024 | 17/6/2026 | The WP Easy Post Types plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… | |
| Analizada | Alta (8.8) | 0.81% | — | Newsignature WP Easy Post Types | 18/10/2024 | 17/6/2026 | The WP Easy Post Types plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 via deserialization of untrusted input from the 'text' parameter in the 'ajax_import_content' function. This allows authenticated attackers, with subscriber-level permissions and above, to inject a… | |
| Modificada | Media (5.4) | 0.41% | — | Newsignature WP Easy Post Types | 18/10/2024 | 17/6/2026 | The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 1.4.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to add,… | |
| Analizada | Media (5.5) | 0.35% | — | Staude Mime Types Extended | 25/6/2024 | 17/6/2026 | The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Aplazada | Media (4.3) | 0.20% | — | Stephanieleary Convert Post TypesAI | 11/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stephanie Leary Convert Post Types.This issue affects Convert Post Types: from n/a through 1.4. | |
| Aplazada | Media (6.4) | 0.43% | — | Metabox Custom Post Types Custom Fields MoreAI | 9/4/2024 | 17/6/2026 | The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and custom post meta in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping on user supplied post meta values. This makes it possible… | |
| Aplazada | Alta (7.1) | 0.35% | — | Stephanieleary Convert Post TypesAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stephanie Leary Convert Post Types allows Reflected XSS.This issue affects Convert Post Types: from n/a through 1.4. | |
| Aplazada | Alta (7.2) | 0.76% | — | Onthegosystems TypesAI | 26/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in OnTheGoSystems Types.This issue affects Types: from n/a through 3.4.17. | |
| Modificada | Alta (8.8) | 0.26% | — | Halgatewood Dashicons + Custom Post Types | 21/12/2023 | 17/6/2026 | Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + Custom Post Types: from n/a through 1.0.2. |