Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.27% | — | Ayecode UserswpAI | 18/6/2026 | 18/6/2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter due to missing validation on a user controlled key. This makes it… | |
| Aplazada | Crítica (9.3) | 0.43% | — | UserspiceAI | 23/5/2026 | 6/10/2026 | userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify existing accounts in the… | |
| Aplazada | Media (5.1) | 0.15% | — | UserspiceAI | 23/5/2026 | 6/10/2026 | userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP header. Attackers can send crafted requests to the backup.php endpoint with XSS payloads in the X-Forwarded-For header that execute when administrators visit the audit log… | |
| Aplazada | Media (6.4) | 0.32% | — | Faces OF UsersAI | 20/5/2026 | 24/7/2026 | The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in the 'facesofusers' shortcode in all versions up to, and including, 0.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.8) | 0.70% | — | Huggingface Diffusers | 14/5/2026 | 17/6/2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hugging Face Hub repositories. The _resolve_custom_pipeline_and_cls function in pipeline_loading_utils.py performs string… | |
| Modificada | Alta (8.8) | 0.89% | — | Huggingface Diffusers | 14/5/2026 | 28/8/2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulnerability has three variants, all sharing… | |
| Aplazada | Alta (8.8) | 0.72% | — | Codection Import AND Export Users AND CustomersAI | 2/5/2026 | 17/6/2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary site (e.g.,… | |
| Aplazada | Media (5) | 0.45% | — | Ayecode UserswpAI | 11/4/2026 | 17/6/2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Server-Side Request Forgery in all versions up to, and including, 1.2.58. This is due to insufficient URL origin validation in the process_image_crop() method when… | |
| Aplazada | Media (4.3) | 0.40% | — | Ayecode UserswpAI | 10/4/2026 | 17/6/2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerable to Improper Access Control in all versions up to, and including, 1.2.58 This is due to insufficient field-level permission validation in the upload_file_remove() AJAX handler where the $htmlvar… | |
| Aplazada | Media (6.4) | 0.42% | — | Ayecode UserswpAI | 9/4/2026 | 17/6/2026 | The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and improper output escaping when rendering user profile data in badge widgets. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 1.3% | — | Users Manager PNAI | 8/4/2026 | 24/7/2026 | The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due to a flawed authorization logic check in the userspn_ajax_nopriv_server() function within the 'userspn_form_save' case. The conditional only blocks… | |
| Analizada | Crítica (9.3) | 0.40% | — | Csprousers Csweb | 23/3/2026 | 17/6/2026 | Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha. | |
| Analizada | Media (5.1) | 0.21% | — | Csprousers Csweb | 23/3/2026 | 17/6/2026 | Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that executes in a victim's browser. Fixed in 8.1.0 alpha. | |
| Analizada | Alta (8.7) | 0.53% | — | Csprousers Csweb | 23/3/2026 | 17/6/2026 | Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha. | |
| Analizada | Alta (8.7) | 0.49% | — | Csprousers Csweb | 23/3/2026 | 17/6/2026 | Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha. | |
| Aplazada | Alta (8.1) | 0.54% | — | Codection Import AND Export Users AND CustomersAI | 21/3/2026 | 17/6/2026 | The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields'… | |
| Aplazada | Alta (8.8) | 0.44% | — | Expire UsersAI | 21/3/2026 | 17/6/2026 | The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_role' meta through the 'save_extra_user_profile_fields' function. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.14% | — | Ayecode UserswpAI | 3/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.53. | |
| Aplazada | Alta (7.2) | 0.24% | — | User Submitted Posts Enable Users TO Submit Posts From THE Front ENDAI | 24/1/2026 | 17/6/2026 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom fields in all versions up to, and including, 20251210 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.5) | 0.33% | — | Latest Registered UsersAI | 7/1/2026 | 17/6/2026 | The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, and including, 1.4. This is due to missing authorization and nonce validation in the rnd_handle_form_submit function hooked to both admin_post_my_simple_form and admin_post_nopriv_my_simple_form… | |
| Aplazada | Alta (7.8) | 0.37% | — | Cogview4AIHuggingface DiffusersAI | 23/12/2025 | 17/6/2026 | Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Diffusers. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Crítica (9.8) | 0.37% | — | Flex Store UsersAI | 20/12/2025 | 17/6/2026 | The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUserHandle::signup' and the 'fsSellerRole::add_role_seller' functions not restricting what user roles a user can register with. This makes it possible for unauthenticated… | |
| Analizada | Alta (8.8) | 0.26% | — | Fastapi-users Project Fastapi Users | 19/12/2025 | 17/6/2026 | FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that could link them to the session that initiated the OAuth flow.… | |
| Aplazada | Media (4.3) | 0.17% | — | Resource Library FOR Logged IN UsersAI | 12/12/2025 | 17/6/2026 | The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various unauthorized actions… | |
| Aplazada | Media (6.4) | 0.22% | — | LjusersAI | 12/12/2025 | 17/6/2026 | The LJUsers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'ljuser' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… |