Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.47% | — | Code-atlantic Content ControlAI | 2/5/2024 | 17/6/2026 | The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.0 via the API. This makes it possible for unauthenticated attackers to extract post titles,… | |
| Aplazada | Alta (7.7) | 0.66% | — | Alfresco Content ServicesAI | 2/5/2024 | 17/6/2026 | An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service. | |
| Aplazada | Media (5.3) | 0.38% | — | Ays-pro Secure Copy Content Protection AND Content LockingAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 3.9.0. | |
| Aplazada | Media (6.4) | 0.35% | — | ContentviewsAI | 25/4/2024 | 17/6/2026 | The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Widget Post Overlay block in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping on… | |
| Aplazada | Media (6.5) | 0.34% | — | Codetides Advanced Floating ContentAI | 24/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Code Tides Advanced Floating Content allows Stored XSS.This issue affects Advanced Floating Content: from n/a through 1.2.5. | |
| Aplazada | Media (5.9) | 0.34% | — | Extendwp Import Content IN Wordpress AND Woocommerce With ExcelAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendWP Import Content in WordPress & WooCommerce with Excel allows Reflected XSS.This issue affects Import Content in WordPress & WooCommerce with Excel: from n/a through 4.2. | |
| Aplazada | Crítica (10) | 0.70% | — | Deepak Anand WP Dummy Content GeneratorAI | 18/4/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator.This issue affects WP Dummy Content Generator: from n/a through <= 3.2.1. | |
| Aplazada | Media (5.3) | 0.36% | — | Stellarwp Restrict ContentAI | 15/4/2024 | 17/6/2026 | Missing Authorization vulnerability in StellarWP Restrict Content.This issue affects Restrict Content: from n/a through 3.2.8. | |
| Aplazada | Media (4.3) | 0.21% | — | Churchthemes Church Content Sermons Events AND MoreAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ChurchThemes Church Content – Sermons, Events and More.This issue affects Church Content – Sermons, Events and More: from n/a through 2.6. | |
| Aplazada | Media (6.1) | 0.49% | — | Creativeminds Invitation Code Content RestrictionAI | 9/4/2024 | 17/6/2026 | The Invitation Code Content Restriction Plugin from CreativeMinds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘target_id’ parameter in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.9) | 0.27% | — | Neliosoftware Nelio ContentAI | 2/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content.This issue affects Nelio Content: from n/a through 3.2.0. | |
| Aplazada | Media (5.3) | 0.36% | — | Deepak Anand WP Dummy Content GeneratorAI | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 3.1.2. | |
| Aplazada | Alta (8.5) | 0.38% | — | Content ManagerAI | 25/3/2024 | 17/6/2026 | By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform unauthorized operations. | |
| Modificada | Media (6.1) | 0.40% | — | Evergreencontentposter Evergreen Content Poster | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poster allows Reflected XSS.This issue affects Evergreen Content Poster: from n/a through 1.4.1. | |
| Aplazada | Alta (7.1) | 0.39% | — | Jose Mortellaro Specific Content FOR Mobile Customize THE Mobile Version Without RedirectionsAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Mortellaro Specific Content For Mobile – Customize the mobile version without redirections allows Reflected XSS.This issue affects Specific Content For Mobile – Customize the mobile version without redirections:… | |
| Aplazada | Alta (7.1) | 0.35% | — | Target-info Mycurator Content CurationAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Tilly MyCurator Content Curation allows Reflected XSS.This issue affects MyCurator Content Curation: from n/a through 3.76. | |
| Analizada | Alta (8.8) | 0.69% | — | Oretnom23 Block Inserter FOR Dynamic Content | 1/3/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Block Inserter for Dynamic Content 1.0 and classified as critical. This vulnerability affects unknown code of the file view_post.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 0.40% | — | IBM Cp4ba - Filenet Content ManagerIBM Filenet Content Manager | 1/3/2024 | 17/6/2026 | IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual circumstances. IBM X-Force ID: 271656. | |
| Analizada | Media (5.3) | 0.75% | — | IBM Filenet Content Manager | 1/3/2024 | 17/6/2026 | IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 261115. | |
| Modificada | Media (4.3) | 0.53% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 29/2/2024 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the creating_pricing_table_page function in all versions up to, and including, 2.11.1. This makes it possible… | |
| Modificada | Media (5.3) | 0.52% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 29/2/2024 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pms_stripe_connect_handle_authorization_return function in all versions up to, and including, 2.11.1.… | |
| Modificada | Media (5.3) | 0.60% | — | Wpexpertdeveloper WP Private Content Plus | 28/2/2024 | 17/6/2026 | The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.6. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view… | |
| Modificada | Alta (7.5) | 0.99% | — | Cusg Content Management System | 14/2/2024 | 17/6/2026 | Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component. | |
| Modificada | Media (6.1) | 0.61% | — | Cusg Content Management System | 14/2/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component. | |
| Modificada | Media (6.1) | 0.61% | — | Cusg Content Management System | 14/2/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component. |