Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 2.4% | 💥 Exploit | WebidAI | 13/8/2025 | 16/6/2026 | WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the to parameter of a POST request is written directly into includes/currencies.php. This allows unauthenticated attackers to inject arbitrary PHP code, resulting in persistent remote code execution when… | |
| Aplazada | Crítica (9.8) | 1.0% | — | Saleswonder WebinarignitionAI | 24/7/2025 | 17/6/2026 | The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login token generation due to a missing capability check on the `webinarignition_sign_in_support_staff` and `webinarignition_register_support` functions… | |
| Aplazada | Media (5.9) | 0.26% | — | Iwebix WP Featured Content SliderAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IWEBIX WP Featured Content Slider wp-featured-content-slider allows Stored XSS.This issue affects WP Featured Content Slider: from n/a through <= 2.6. | |
| Modificada | Crítica (9.8) | 0.38% | — | Webinarpress | 7/5/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Server Side Request Forgery.This issue affects WebinarPress: from n/a through <= 1.33.28. | |
| Aplazada | Alta (7.1) | 0.29% | — | Webilop Woocommerce Html5 VideoAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webilop WooCommerce HTML5 Video woocommerce-html5-video allows Reflected XSS.This issue affects WooCommerce HTML5 Video: from n/a through <= 1.7.10. | |
| Aplazada | Media (4.7) | 0.42% | — | Webilia INC ListdomAI | 16/4/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Webilia Inc. Listdom listdom allows Phishing.This issue affects Listdom: from n/a through <= 4.0.0. | |
| Modificada | Media (4.7) | 0.38% | — | Webinarpress | 9/4/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Phishing.This issue affects WebinarPress: from n/a through <= 1.33.28. | |
| Modificada | Media (4.8) | 0.23% | — | Webinarpress | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Stored XSS.This issue affects WebinarPress: from n/a through <= 1.33.28. | |
| Modificada | Media (4.3) | 0.29% | — | Webinarpress | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarPress: from n/a through <= 1.33.28. | |
| Aplazada | Media (6.5) | 0.23% | — | Webilia INC Vertex Addons FOR ElementorAI | 17/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder allows Stored XSS.This issue affects Vertex Addons for Elementor: from n/a through <= 1.2.0. | |
| Analizada | Media (4.3) | 0.43% | — | Webinarpress | 8/1/2025 | 17/6/2026 | The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing capability check on several functions in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify webinars. | |
| Analizada | Alta (8.8) | 0.91% | — | Webinarpress | 8/1/2025 | 17/6/2026 | The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.57% | — | Stylemixthemes Eroom Zoom Meetings AND WebinarAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in StylemixThemes eRoom – Zoom Meetings & Webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom – Zoom Meetings & Webinar: from n/a through 1.4.6. | |
| Aplazada | Media (4.3) | 0.40% | — | Northernbeacheswebsites WP GotowebinarAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP GoToWebinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP GoToWebinar: from n/a through 15.6. | |
| Modificada | Alta (8.8) | 0.21% | — | Wpwebinfotech Social Auto Poster | 20/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpweb Social Auto Poster social-auto-poster allows Cross Site Request Forgery.This issue affects Social Auto Poster: from n/a through <= 5.3.15. | |
| Modificada | Media (6.1) | 0.33% | — | Wpwebinfotech Social Auto Poster | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb Social Auto Poster social-auto-poster allows Reflected XSS.This issue affects Social Auto Poster: from n/a through <= 5.3.15. | |
| Analizada | Crítica (9.3) | 12% | 💥 Exploit | Smart-hmi Webiq | 16/9/2024 | 17/6/2026 | The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system. | |
| Analizada | Media (6.1) | 0.38% | — | Uniong Webitr | 9/9/2024 | 17/6/2026 | WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain, can be redirected to another page, potentially leading to phishing attacks. | |
| Analizada | Media (6.1) | 0.17% | — | Webinarpress | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20. | |
| Aplazada | Alta (7.1) | 0.16% | — | Northernbeacheswebsites WP GotowebinarAI | 2/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This issue affects WP GoToWebinar: from n/a through 15.7. | |
| Modificada | Alta (8.8) | 0.79% | — | Wpwebinfotech Social Auto Poster | 24/7/2024 | 17/6/2026 | The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Contributor-level and above permissions, to… | |
| Modificada | Media (5.3) | 0.32% | — | Wpwebinfotech Social Auto Poster | 24/7/2024 | 17/6/2026 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multiple’ function in all versions up to, and including, 5.3.14. This makes it possible for unauthenticated attackers to delete arbitrary posts. | |
| Modificada | Media (4.3) | 0.26% | — | Wpwebinfotech Social Auto Poster | 24/7/2024 | 17/6/2026 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Modificada | Media (6.1) | 0.82% | 💥 Exploit | Wpwebinfotech Social Auto Poster | 24/7/2024 | 17/6/2026 | The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Media (5.4) | 0.26% | — | Wpwebinfotech Social Auto Poster | 24/7/2024 | 17/6/2026 | The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for… |