Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.25% | — | Pickplugins JOB Board ManagerAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Job Board Manager allows Stored XSS.This issue affects Job Board Manager: from n/a through 2.1.57. | |
| Analizada | Media (5.4) | 0.36% | — | Goldplugins Easy Testimonials | 20/7/2024 | 17/6/2026 | The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_grid ' shortcode in all versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Aplazada | Media (6.5) | 0.50% | — | Blue Plugins Events Calendar FOR GoogleAI | 12/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Blue Plugins Events Calendar for Google allows PHP Local File Inclusion.This issue affects Events Calendar for Google: from n/a through 2.1.0. | |
| Aplazada | Alta (8.5) | 0.51% | — | Pluginsware Advanced Classifieds AND Directory PROAI | 9/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginsWare Advanced Classifieds & Directory Pro allows Path Traversal.This issue affects Advanced Classifieds & Directory Pro: from n/a through 3.1.3. | |
| Modificada | Media (6.5) | 0.57% | — | Smartypantsplugins SP Project & Document Manager | 9/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.71. | |
| Modificada | Media (5.4) | 0.34% | — | Wpexpertplugins Post Meta Data Manager | 2/7/2024 | 17/6/2026 | The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Alta (8.8) | 0.46% | — | Weplugins WP MapsAI | 29/6/2024 | 17/6/2026 | The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Modificada | Media (4.8) | 0.26% | — | 5starplugins Easy AGE Verify | 21/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 5 Star Plugins Easy Age Verify allows Stored XSS.This issue affects Easy Age Verify: from n/a through 1.8.2. | |
| Analizada | Media (6.5) | 2.6% | 💥 Exploit | Bplugins Html5 Video Player | 20/6/2024 | 17/6/2026 | The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks | |
| Modificada | Media (5.4) | 0.39% | — | Kraftplugins Wheel OF Life | 20/6/2024 | 17/6/2026 | The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the AjaxFunctions.php file in all versions up to, and including, 1.1.7. This makes it possible for authenticated… | |
| Modificada | Media (4.8) | 0.34% | — | Fooplugins Foobox | 18/6/2024 | 17/6/2026 | The Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plugin before 2.7.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html… | |
| Aplazada | Alta (7.1) | 0.51% | — | Fooplugins Fooevents FOR WoocommerceAI | 15/6/2024 | 17/6/2026 | The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability setting on the 'display_ticket_themes_page' function in versions up to, and including, 1.19.20. This makes it possible for authenticated attackers with contributor-level capabilities or… | |
| Modificada | Media (5.4) | 0.47% | — | Fooplugins Foogallery | 14/6/2024 | 17/6/2026 | The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up to, and including, 2.4.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.37% | — | Fooplugins Foogallery | 13/6/2024 | 17/6/2026 | The FooGallery WordPress plugin before 2.4.15, foogallery-premium WordPress plugin before 2.4.15 does not validate and escape some of its Gallery settings before outputting them back in the page, which could allow users with a role as low as Author to perform Stored Cross-Site Scripting attacks which could be used… | |
| Analizada | Alta (8.8) | 0.38% | — | Plugins360 All-in-one Video Gallery | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Team Plugins360 All-in-One Video Gallery.This issue affects All-in-One Video Gallery: from n/a through 3.5.2. | |
| Modificada | Alta (8.8) | 1.0% | 💥 PoC | Xlplugins Finale | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0. | |
| Modificada | Alta (8.8) | 1.4% | 💥 PoC | Xlplugins Nextmove | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0. | |
| Modificada | Media (5.4) | 0.26% | — | Pickplugins Comboblocks | 7/6/2024 | 17/6/2026 | The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the menu-wrap-item block in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output… | |
| Modificada | Media (5.4) | 0.26% | — | Pickplugins Post Grid | 7/6/2024 | 17/6/2026 | The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute in blocks in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. This makes… | |
| Modificada | Media (4.3) | 0.36% | — | Fivestarplugins Five Star Restaurant Menu | 5/6/2024 | 17/6/2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (6.3) | 0.28% | — | Spiffyplugins Spiffy Calendar | 4/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10. | |
| Modificada | Media (5.4) | 0.25% | — | Spiffyplugins WP Flow Plus | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus allows Stored XSS.This issue affects WP Flow Plus: from n/a through 5.2.2. | |
| Aplazada | Media (5.4) | 0.43% | — | Pickplugins Tabs & AccordionAI | 4/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in PickPlugins Tabs & Accordion allows Code Injection.This issue affects Tabs & Accordion: from n/a through 1.3.10. | |
| Analizada | Media (5.3) | 0.48% | — | Wpplugins Hide MY WP Ghost | 4/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25. | |
| Aplazada | Media (6.5) | 0.67% | — | Wpfactory Download Plugins AND Themes From DashboardAI | 22/5/2024 | 17/6/2026 | Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server. |