Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Ecommerce WebsiteAI | 4/7/2026 | 7/7/2026 | A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (5.5) | 0.69% | — | Jairiidriss Restaurant-website-php-mysqlAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a manipulation results in missing authentication. The attack is possible to be carried… | |
| Aplazada | Media (5.5) | 0.52% | — | Klik SocialmediawebsiteAI | 25/5/2026 | 23/7/2026 | A vulnerability was identified in KLiK SocialMediaWebsite 1.0. This issue affects some unknown processing of the component HTTP POST Request Parameter Handler. Such manipulation leads to injection. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.50% | — | Klik SocialmediawebsiteAI | 25/5/2026 | 23/7/2026 | A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File Handler. This manipulation causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (2.1) | 0.42% | — | Klik SocialmediawebsiteAI | 25/5/2026 | 23/7/2026 | A vulnerability was found in KLiK SocialMediaWebsite 1.0. This affects an unknown part of the component HTTP GET Request Parameter Handler. The manipulation results in injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Akilli Commerce Software Technologies E-commerce WebsiteAI | 14/5/2026 | 17/6/2026 | Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: before 4.5.001. | |
| Aplazada | Crítica (9.8) | 0.36% | — | Akilli Commerce Software Technologies E-commerce WebsiteAI | 14/5/2026 | 30/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL Injection. This issue affects E-Commerce Website: before 4.5.001. | |
| Aplazada | Crítica (9.8) | 0.26% | — | Akilli Commerce Software Technologies LTD CO E Commerce WebsiteAI | 12/5/2026 | 30/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows SQL Injection. This issue affects E-Commerce Website: before 4.5.001. | |
| Aplazada | Baja (2.1) | 1.8% | — | Pskill9 Website-downloaderAI | 2/5/2026 | 17/6/2026 | A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument outputPath results in os command injection. The attack may be initiated remotely. The exploit is now… | |
| Aplazada | Media (6.9) | 0.40% | — | Klik SocialmediawebsiteAI | 25/4/2026 | 17/6/2026 | A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Executing a manipulation of the argument c_id can lead to sql injection. It is possible to launch the attack remotely. | |
| Aplazada | Media (6.4) | 0.25% | — | Gallagher Website DesignAI | 22/4/2026 | 17/6/2026 | The Gallagher Website Design plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's login_link shortcode in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on the 'prefix' attribute. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.4) | 0.24% | — | Website Llms TXTAI | 21/4/2026 | 17/6/2026 | The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Media (6.1) | 0.29% | — | Website Llms TXTAI | 21/4/2026 | 17/6/2026 | The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.6. This is due to the use of filter_input() without a sanitization filter and insufficient output escaping. This makes it possible for unauthenticated attackers to… | |
| Analizada | Alta (8.8) | 0.40% | — | Phpscriptsmall News Website Script | 5/4/2026 | 24/7/2026 | News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers can send GET requests to index.php/show/news/ with malicious SQL statements to extract sensitive database information. | |
| Aplazada | Media (6.5) | 0.22% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows DOM-Based XSS.This issue affects WP Custom Admin Interface: from n/a through <= 7.42. | |
| Aplazada | Alta (8.8) | 0.33% | — | Matrimony Website Script M-plusAI | 24/3/2026 | 17/6/2026 | Matrimony Website Script M-Plus contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through various POST parameters. Attackers can inject malicious SQL payloads into parameters like txtGender, religion, Fage, and cboCountry across… | |
| Aplazada | Alta (7.1) | 0.25% | — | Ryan Howard Website Llms.txtAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Website LLMs.txt website-llms-txt allows Reflected XSS.This issue affects Website LLMs.txt: from n/a through <= 8.2.6. | |
| Analizada | Media (5.5) | 0.61% | — | Oretnom23 Simple Responsive Tourism Website | 8/3/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of the component Login. This manipulation of the argument Username causes sql injection. The attack may be initiated… | |
| Aplazada | Media (4.3) | 0.29% | — | Winston AI Humn-1 AI Website ScannerAI | 7/3/2026 | 17/6/2026 | The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the winston_disconnect() function in all versions up to, and including, 0.0.3. This makes it possible for authenticated attackers, with… | |
| Analizada | Baja (2.1) | 0.43% | — | Remyandrade Website Link Extractor | 25/2/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function file_get_contents of the component URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.59% | — | Oretnom23 Simple Responsive Tourism Website | 20/2/2026 | 17/6/2026 | A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component Registration. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Crítica (10) | 0.48% | — | Ogp-websiteAI | 19/2/2026 | 17/6/2026 | OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in authentication bypass without knowledge of the victim account's password. | |
| Aplazada | Alta (8.6) | 0.31% | — | Zirve Information Technologies INC E-taxpayer Accounting WebsiteAI | 9/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. E-Taxpayer Accounting Website allows Reflected XSS. This issue affects e-Taxpayer Accounting Website: through 07082025. | |
| Analizada | Baja (2.1) | 0.31% | — | Oretnom23 Simple Responsive Tourism Website | 8/2/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Master.php?f=save_package. The manipulation of the argument Title leads to cross site scripting. The attack can be initiated remotely. The… | |
| Analizada | Baja (2.1) | 0.41% | — | Oretnom23 Simple Responsive Tourism Website | 8/2/2026 | 17/6/2026 | A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the file /tourism/classes/Master.php?f=register of the component Registration. Executing a manipulation of the argument firstname/lastname/username can lead to cross site scripting. It is possible to… |