Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
721 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.76% | — | Warfareplugins Social Warfare | 19/1/2023 | 17/6/2026 | The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete post meta information and reset… | |
| Modificada | Media (5.4) | 0.47% | — | Heateor Super Socializer | 16/1/2023 | 17/6/2026 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used… | |
| Modificada | Media (5.4) | 0.51% | — | Smashballoon Smash Balloon Social Post Feed | 16/1/2023 | 17/6/2026 | The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. | |
| Modificada | Media (5.4) | 0.47% | — | Heateor Sassy Social Share | 16/1/2023 | 17/6/2026 | The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (4.8) | 0.60% | — | WP Social Sharing Project WP Social Sharing | 2/1/2023 | 17/6/2026 | The WP Social Sharing WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (8.8) | 1.4% | 💥 PoC | Klik-socialmediawebsite Project Klik-socialmediawebsite | 22/11/2022 | 17/6/2026 | KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php. | |
| Modificada | Media (6.5) | 0.73% | — | Adenion Blog2social | 25/10/2022 | 17/6/2026 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks | |
| Modificada | Alta (8.8) | 1.2% | — | Adenion Blog2social | 25/10/2022 | 17/6/2026 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers | |
| Modificada | Media (4.8) | 0.58% | — | Mekshq Meks Easy Social Share | 17/10/2022 | 17/6/2026 | The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.59% | — | Wpsocialrocket Social Rocket | 10/10/2022 | 17/6/2026 | The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.73% | — | WP Socializer Project WP Socializer | 3/10/2022 | 17/6/2026 | The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.50% | — | Spacexchimp Social Media Follow Buttons BAR | 30/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73 at WordPress. | |
| Modificada | Media (6.1) | 0.77% | — | Slickremix Feed Them Social | 22/8/2022 | 17/6/2026 | The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 6.5% | 💥 Exploit | Slickremix Feed Them Social | 22/8/2022 | 17/6/2026 | The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.62% | — | Quadlayers WP Social Chat | 22/8/2022 | 17/6/2026 | The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.5) | 1.4% | — | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home. | |
| Modificada | Media (5.4) | 1.1% | 💥 PoC | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module. | |
| Modificada | Alta (7.2) | 2.1% | — | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior… | |
| Modificada | Media (4.8) | 0.89% | — | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the SitePages module. | |
| Modificada | Media (5.4) | 1.1% | 💥 PoC | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module. | |
| Modificada | Media (5.4) | 1.1% | 💥 PoC | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module. | |
| Modificada | Alta (8.8) | 0.98% | — | Supsystic Social Share Buttons | 22/7/2022 | 17/6/2026 | Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress. | |
| Modificada | Alta (8.8) | 0.92% | — | Supsystic Social Share Buttons | 22/7/2022 | 17/6/2026 | Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress. | |
| Modificada | Media (4.8) | 0.52% | — | Social Media Share Buttons Project Social Media Share Buttons | 20/7/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons plugin <= 3.8.1 at WordPress. | |
| Modificada | Crítica (9.8) | 1.7% | — | Slickremix Feed Them Social | 18/7/2022 | 17/6/2026 | The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a PHAR wrapper that will deserialize the data… |