Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.44% | — | Enrico Cantori 3D Avatar User ProfileAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enrico Cantori 3D Avatar User Profile 3d-avatar-user-profile allows Reflected XSS.This issue affects 3D Avatar User Profile: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.3) | 0.43% | — | Josevega Display Custom Fields IN THE Frontend Post AND User Profile FieldsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jose Vega Display custom fields in the frontend – Post and User Profile Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display custom fields in the frontend – Post and User Profile Fields: from n/a through 1.2.0. | |
| Modificada | Media (4.3) | 0.41% | — | Cozmoslabs User Profile Picture | 21/6/2024 | 17/6/2026 | The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access… | |
| Analizada | Media (5.4) | 0.42% | — | Wpeventsmanager User Profile Avatar | 15/4/2024 | 17/6/2026 | The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (6.3) | 0.38% | — | Pickplugins User ProfileAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins User profile allows Stored XSS.This issue affects User profile: from n/a through 2.0.20. | |
| Modificada | Alta (8.8) | 1.1% | — | Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to insufficient input validation and restriction on access to that shortcode. This makes it possible… | |
| Modificada | Media (4.3) | 0.47% | — | Josevega Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.1 via the vg_display_data shortcode due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.41% | — | Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and postmeta in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Modificada | Media (4.3) | 0.40% | — | Wp-eventmanager User Profile Avatar | 22/1/2024 | 17/6/2026 | The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar | |
| Modificada | Media (5.4) | 0.64% | — | Export User Project Export User | 14/4/2023 | 17/6/2026 | The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Modificada | Media (5.4) | 0.40% | — | Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms | 16/3/2023 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions. | |
| Modificada | Media (6.1) | 0.48% | — | ADD User Project ADD User | 27/2/2023 | 17/6/2026 | The Custom Add User WordPress plugin through 2.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.55% | — | Paidmembershipspro Custom User Profile Fields FOR User Registration | 30/1/2023 | 17/6/2026 | The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against… | |
| Modificada | Crítica (9.8) | 4.8% | — | WP User Project WP User | 2/1/2023 | 17/6/2026 | The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | |
| Modificada | Media (6.5) | 2.3% | — | User-meta User Meta User Profile Builder AND User Management | 8/6/2022 | 17/6/2026 | The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads | |
| Modificada | Media (4.8) | 0.59% | — | User-meta User Meta User Profile Builder AND User Management | 30/5/2022 | 17/6/2026 | The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (4.8) | 0.60% | — | Wpsheeteditor Bulk Edit AND Create User Profiles - WP Sheet Editor | 16/5/2022 | 17/6/2026 | The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.1) | 0.80% | — | WP User Project WP User | 28/2/2022 | 17/6/2026 | The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (6.1) | 1.0% | — | Profilepress User Registration, Login Form, User Profile & Membership | 13/12/2021 | 17/6/2026 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 1.0% | — | Profilepress User Registration, Login Form, User Profile & Membership | 13/12/2021 | 17/6/2026 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Crítica (9.8) | 1.3% | — | SET User Project SET User | 27/9/2021 | 17/6/2026 | The set_user extension module before 3.0.0 for PostgreSQL allows ProcessUtility_hook bypass via set_config. | |
| Modificada | Crítica (9.8) | 1.3% | — | SET User Project SET User | 10/8/2021 | 17/6/2026 | The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AUTHORIZATION after set_user(). | |
| Modificada | Media (5.4) | 0.78% | — | Cozmoslabs User Profile Picture | 2/8/2021 | 17/6/2026 | The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles). | |
| Modificada | Media (6.1) | 1.1% | — | Flask-user Project Flask-user | 5/7/2021 | 17/6/2026 | This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as /////evil.com/path or \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server… | |
| Modificada | Alta (7.5) | 4.8% | — | Cozmoslabs User Profile Picture | 5/4/2021 | 17/6/2026 | The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information. |