Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.58% | — | Suiteplugins Video AND Photo Gallery FOR Ultimate MemberAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-ultimate-member allows SQL Injection.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through <= 1.1.3. | |
| Aplazada | Media (4.9) | 0.19% | — | Suiteplugins Video & Photo Gallery FOR Ultimate MemberAI | 27/3/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-ultimate-member allows Server Side Request Forgery.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.5) | 0.79% | — | Suiteplugins Login Widget FOR Ultimate MemberAI | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SuitePlugins Login Widget for Ultimate Member login-widget-for-ultimate-member allows PHP Local File Inclusion.This issue affects Login Widget for Ultimate Member: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.5) | 0.72% | — | Ultimatemember Ultimate MemberAI | 5/3/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 2.10.0 due to insufficient escaping on the user supplied parameter and lack… | |
| Analizada | Media (6.5) | 0.36% | — | Ultimatemember Ultimate Member | 21/2/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the user supplied parameter and lack of… | |
| Analizada | Media (5.3) | 0.36% | — | Ultimatemember Ultimate Member | 18/1/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for unauthenticated… | |
| Analizada | Alta (7.5) | 0.53% | — | Ultimatemember Ultimate Member | 18/1/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Crítica (9.9) | 0.66% | — | Suiteplugins Video AND Photo Gallery FOR Ultimate MemberAI | 16/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-ultimate-member allows Upload a Web Shell to a Web Server.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through <= 1.1.0. | |
| Aplazada | Media (6.1) | 0.42% | — | Video Photo Gallery FOR Ultimate MemberAI | 12/12/2024 | 17/6/2026 | The Video & Photo Gallery for Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Analizada | Media (4.3) | 0.58% | — | Ultimatemember Ultimate Member | 21/11/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and ajax_resize_image() functions in all versions up to, and… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Wpindeed Ultimate Membership PROAI | 16/10/2024 | 17/6/2026 | The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID. | |
| Analizada | Media (4.3) | 0.34% | — | Ultimatemember Ultimate Member | 4/10/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the admin_init or user_action_hook… | |
| Analizada | Media (5.4) | 0.44% | — | Ultimatemember Ultimate Member | 4/10/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output… | |
| Modificada | Crítica (10) | 0.54% | — | Wpindeed Ultimate Membership PRO | 19/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Modificada | Crítica (9.8) | 0.55% | — | Wpindeed Ultimate Membership PRO | 19/8/2024 | 17/6/2026 | Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpindeed Ultimate Membership PROAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Modificada | Media (5.4) | 0.50% | — | Ultimatemember Ultimate Member | 2/5/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output… | |
| Analizada | Crítica (9.8) | 89% | 💥 Exploit | Ultimatemember Ultimate Member | 13/3/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Modificada | Media (6.1) | 27% | — | Ultimatemember Ultimate Member | 13/3/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This… | |
| Modificada | Alta (8.8) | 0.27% | — | Ultimatemember Ultimate Member | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions. | |
| Modificada | Crítica (9.8) | 72% | 💥 Exploit | Ultimatemember Ultimate Member | 4/7/2023 | 17/6/2026 | The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild. | |
| Modificada | Alta (7.2) | 3.0% | — | Ultimatemember Ultimate Member | 29/11/2022 | 17/6/2026 | The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). This is restricted to non-parameter PHP functions like phpinfo(); since user… | |
| Modificada | Alta (7.2) | 3.0% | — | Ultimatemember Ultimate Member | 29/11/2022 | 17/6/2026 | The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it through call_user_func(). This makes it possible for authenticated attackers, with administrative… | |
| Modificada | Media (4.3) | 2.7% | — | Ultimatemember Ultimate Member | 29/11/2022 | 17/6/2026 | The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribute used in shortcodes. This makes it possible for attackers with administrative privileges to supply arbitrary paths using traversal… | |
| Modificada | Alta (7.5) | 0.77% | — | Ultimatemember Ultimate Member | 13/11/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_template of the file includes/core/class-shortcodes.php of the component Template Handler. The manipulation of the argument tpl leads to pathname traversal. The attack may be… |