Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

644 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.29%—Supsystic Ultimate MapsAI3/9/20265/9/2026
Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.
AplazadaMedia (5.3)0.31%—Wpswings Ultimate Gift Cards FOR WoocommerceAI2/9/20262/9/2026
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
AplazadaMedia (5.3)0.23%—Ultimatemember Ultimate MemberAI2/9/20263/9/2026
The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning profile activity to unauthenticated visitors, allowing them to read the content of comments still awaiting moderation.
AplazadaMedia (6.8)0.29%—Codeinwp Ultimate Before After Image Slider AND GalleryAI2/9/20263/9/2026
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including…
AplazadaMedia (6.8)0.29%—Ultimate Before After Image Slider GalleryAI2/9/20263/9/2026
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an…
AplazadaMedia (5.3)0.41%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal.
AplazadaAlta (8.9)0.43%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict MIME verification and GD binary raster…
AplazadaAlta (8.6)0.42%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual escaping, allowing injection of malicious…
AplazadaMedia (5.1)0.39%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or core.admin). An authenticated user could submit…
AplazadaMedia (5.1)0.39%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image path (src) belonged to that article. On…
AplazadaMedia (4.1)0.31%—Smackcoders WP Ultimate CSV ImporterAI29/8/202631/8/2026
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.
AplazadaAlta (8.1)0.23%—Ultimatemember Ultimate MemberAI28/8/202628/8/2026
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register…
AplazadaMedia (6.4)0.35%—Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI26/8/202626/8/2026
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)0.28%—Ultimatemember Ultimate MemberAI25/8/202628/9/2026
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) in all versions up to, and including, 2.12.1 due to…
AplazadaCrítica (9.9)0.48%—UltimateaiAI24/8/202627/8/2026
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
AplazadaMedia (6.8)0.43%—Post Grid Slider Carousel UltimateAI22/8/202626/8/2026
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any…
AplazadaAlta (7.5)0.35%—Supsystic Ultimate MapsAI18/8/202620/8/2026
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
AplazadaCrítica (9.8)0.56%—Supsystic Ultimate MapsAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
AplazadaAlta (7.1)0.25%—Supsystic Ultimate MapsAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
AplazadaAlta (7.1)0.25%—Mapsteps UG Ultimate Dashboard PROAI18/8/20265/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Dashboard Ultimate Dashboard Pro ultimate-dashboard-pro allows DOM-Based XSS.This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2.
AplazadaMedia (4.8)0.20%—Ultimate POSAI12/8/202624/9/2026
Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary HTML and script markup by setting a malicious payload in the user first-name field during account creation. Attackers with a low-privileged role…
AplazadaMedia (6.5)0.22%—Brainstormforce Ultimate Addons FOR ElementorAI6/8/202612/8/2026
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
AplazadaMedia (6.5)0.27%—Ultimate Store KIT Elementor AddonsAI6/8/202612/8/2026
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
AplazadaMedia (6.1)0.25%—Ultimate Addons FOR WpbakeryAI31/7/202626/8/2026
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(),
AplazadaAlta (8.1)0.38%—Ultimatemember Ultimate MemberAI31/7/202626/8/2026
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role…