Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
226 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.55% | — | Advanced ViewsAI | 1/8/2026 | 12/8/2026 | The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the register_rest_routes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.42% | — | Rich Showcase FOR Google ReviewsAI | 24/7/2026 | 24/7/2026 | The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Crítica (9.9) | 0.79% | — | Advanced ViewsAI | 23/7/2026 | 23/7/2026 | Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. | |
| Aplazada | Media (4.8) | 0.13% | — | Smashballoon Reviews FeedAI | 20/7/2026 | 21/7/2026 | The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the… | |
| Aplazada | Media (6.5) | 0.43% | — | Cusrev Customer Reviews FOR WoocommerceAI | 16/7/2026 | 16/7/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files (bounded to an image and video allowlist)… | |
| Aplazada | Media (5.3) | 0.33% | — | Crocoblock JET ReviewsAI | 13/7/2026 | 13/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Aman CF7 ViewsAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views – Complete Entry Management for Contact Form 7 cf7-views allows DOM-Based XSS.This issue affects CF7 Views – Complete Entry Management for Contact Form 7: from n/a through <= 3.2.2. | |
| Aplazada | Media (4.4) | 0.40% | — | Widgets FOR Google ReviewsAI | 11/7/2026 | 13/7/2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to… | |
| Aplazada | Media (6.4) | 0.42% | — | Cusrev Customer Reviews FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (6.4) | 0.33% | — | Reviews Widgets FOR Google Yelp AND TripadvisorAI | 6/7/2026 | 7/7/2026 | The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev()… | |
| Aplazada | Media (6.5) | 0.22% | — | JetreviewsAI | 2/7/2026 | 2/7/2026 | Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions. | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | Zaproxy ZAPAIZaproxy Viewstate Add-onAI | 26/6/2026 | 14/7/2026 | Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The… | |
| Aplazada | Media (6.5) | 0.37% | — | Geminilabs Site ReviewsAI | 26/6/2026 | 26/6/2026 | Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Cusrev Customer Reviews FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. | |
| Aplazada | Media (4.3) | 0.42% | — | Reviews AND Rating DocplannerAI | 24/6/2026 | 25/6/2026 | The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Media (5.3) | 0.47% | — | Helpfulcrowd Product ReviewsAI | 9/6/2026 | 23/7/2026 | The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1.2.9. This is due to the `helpfulcrowd_validate_token()` function using a loose comparison operator (`!=`) instead of a strict comparison (`!==`) when validating the… | |
| Aplazada | Alta (8.5) | 0.36% | — | Aman Views Views FOR Wpforms LiteAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite allows Blind SQL Injection.This issue affects Views for WPForms: from n/a through <= 3.4.6. | |
| Aplazada | Alta (8.5) | 0.36% | — | Aman Views FOR Ninja FormsAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend views-for-ninja-forms allows Blind SQL Injection.This issue affects Ninja Forms Views – Display & Edit Ninja… | |
| Aplazada | Media (6.1) | 0.29% | — | Cusrev Customer Reviews FOR WoocommerceAI | 16/4/2026 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.57% | — | Cusrev Customer Reviews FOR WoocommerceAI | 10/4/2026 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta value using strict… | |
| Aplazada | Media (5.9) | 0.24% | — | Richplugins Rich Showcase FOR Google ReviewsAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins Rich Showcase for Google Reviews widget-google-reviews allows Stored XSS.This issue affects Rich Showcase for Google Reviews: from n/a through <= 6.9.4.3. | |
| Aplazada | Media (4.8) | 0.41% | — | Dato CMSAIDato WEB PreviewsAI | 27/2/2026 | 17/6/2026 | Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated user to circumvent the restriction enforced on the configured frontend URL, enabling the loading of arbitrary external resources or origins. This issue affects Web Previews < v1.0.31. | |
| Aplazada | Media (5.3) | 0.34% | — | Villatheme Woocommerce Photo ReviewsAI | 26/2/2026 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews allows Code Injection.This issue affects WooCommerce Photo Reviews: from n/a through <= 1.4.4. | |
| Aplazada | Media (5.4) | 0.29% | — | BBR Plugins Better Business ReviewsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1. | |
| Aplazada | Alta (7.2) | 0.27% | — | Gowebsolutions WP Customer ReviewsAI | 19/2/2026 | 17/6/2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… |