Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.40% | — | Gvectors Wpforo Forum | 28/2/2026 | 17/6/2026 | wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment via the wpforo_synch_roles AJAX handler. Attackers access the usergroups admin page, accessible to any authenticated user, to obtain a nonce, then remap all wpForo… | |
| Analizada | Media (5.3) | 0.31% | — | Gvectors Wpforo Forum | 28/2/2026 | 17/6/2026 | wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge, or split any forum topic via the topic_move, topic_merge, and topic_split form action handlers. Attackers with a valid form nonce can reorganize arbitrary forum content without moderator… | |
| Analizada | Media (5.3) | 0.38% | — | Gvectors Wpforo Forum | 28/2/2026 | 17/6/2026 | wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reopen any forum topic via the wpforo_close_ajax handler. Attackers submit a valid nonce with an arbitrary topic ID to bypass the moderator permission requirement and disrupt forum discussions. | |
| Analizada | Media (5.3) | 0.38% | — | Gvectors Wpforo Forum | 28/2/2026 | 17/6/2026 | wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or unapprove any forum post via the wpforo_approve_ajax AJAX handler. Attackers exploit the nonce-only check by submitting a valid nonce with an arbitrary post ID to bypass moderation controls entirely. | |
| Aplazada | Alta (7.5) | 2.6% | — | Gvectors WpforoAI | 19/2/2026 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.53% | — | Gvectors WpforoAI | 11/2/2026 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP… | |
| Aplazada | Alta (7.5) | 0.28% | — | Gvectors WpforoAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.10. | |
| Aplazada | Alta (7.5) | 0.38% | — | Gvectors WpforoAI | 14/12/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.28% | — | Gvectors WpforoAI | 1/11/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.5) | 0.37% | — | Gvectors WpforoAI | 25/10/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT… | |
| Aplazada | Media (4.3) | 0.34% | — | Gvectors WpforoAI | 3/9/2025 | 30/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.6. | |
| Aplazada | Media (5.4) | 0.23% | — | Gvectors WpforoAI | 10/7/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary… | |
| Aplazada | Alta (7.2) | 0.24% | — | Wpforo Advanced AttachmentsAIGvectors WpforoAI | 3/6/2025 | 17/6/2026 | The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and… | |
| Aplazada | Alta (7.6) | 0.29% | — | Gvectors Wpforo ForumAI | 4/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Tomdever wpForo Forum wpforo allows Privilege Escalation.This issue affects wpForo Forum: from n/a through <= 2.4.2. | |
| Analizada | Media (6.5) | 0.38% | — | Gvectors Wpforo Forum | 28/2/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary… | |
| Modificada | Media (5.4) | 0.30% | — | Gvectors Wpforo Forum | 9/12/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Code Injection.This issue affects wpForo Forum: from n/a through 2.2.5. | |
| Analizada | Alta (7.5) | 0.45% | — | Gvectors Wpforo Forum | 26/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4. | |
| Analizada | Alta (8.1) | 0.31% | — | Gvectors Wpforo Forum | 18/8/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4. | |
| Modificada | Media (5.4) | 0.27% | — | Gvectors Wpforo Forum | 21/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Content Spoofing.This issue affects wpForo Forum: from n/a through 2.0.9. | |
| Modificada | Media (6.5) | 0.46% | — | Gvectors Wpforo Forum | 1/6/2024 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Crítica (9.8) | 0.47% | — | Gvectors Wpforo Forum | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.3. | |
| Modificada | Alta (8.8) | 0.27% | — | Gvectors Wpforo Forum | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a through 2.2.6. | |
| Modificada | Media (5.4) | 0.38% | — | Gvectors Wpforo Forum | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.This issue affects wpForo Forum: from n/a through 2.2.3. | |
| Modificada | Media (6.1) | 0.84% | — | Gvectors Wpforo Forum | 24/7/2023 | 17/6/2026 | The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability. | |
| Modificada | Alta (8.8) | 61% | — | Gvectors Wpforo Forum | 9/6/2023 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it… |