Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

721 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.76%—Warfareplugins Social Warfare19/1/202317/6/2026
The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete post meta information and reset…
ModificadaMedia (5.4)0.47%—Heateor Super Socializer16/1/202317/6/2026
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used…
ModificadaMedia (5.4)0.51%—Smashballoon Smash Balloon Social Post Feed16/1/202317/6/2026
The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
ModificadaMedia (5.4)0.47%—Heateor Sassy Social Share16/1/202317/6/2026
The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as…
ModificadaMedia (4.8)0.60%—WP Social Sharing Project WP Social Sharing2/1/202317/6/2026
The WP Social Sharing WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaAlta (8.8)1.4%💥 PoCKlik-socialmediawebsite Project Klik-socialmediawebsite22/11/202217/6/2026
KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.
ModificadaMedia (6.5)0.73%—Adenion Blog2social25/10/202217/6/2026
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks
ModificadaAlta (8.8)1.2%—Adenion Blog2social25/10/202217/6/2026
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers
ModificadaMedia (4.8)0.58%—Mekshq Meks Easy Social Share17/10/202217/6/2026
The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (4.8)0.59%—Wpsocialrocket Social Rocket10/10/202217/6/2026
The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (4.8)0.73%—WP Socializer Project WP Socializer3/10/202217/6/2026
The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (4.8)0.50%—Spacexchimp Social Media Follow Buttons BAR30/9/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73 at WordPress.
ModificadaMedia (6.1)0.77%—Slickremix Feed Them Social22/8/202217/6/2026
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)6.5%💥 ExploitSlickremix Feed Them Social22/8/202217/6/2026
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (4.8)0.62%—Quadlayers WP Social Chat22/8/202217/6/2026
The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (7.5)1.4%—Openteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home.
ModificadaMedia (5.4)1.1%💥 PoCOpenteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module.
ModificadaAlta (7.2)2.1%—Openteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior…
ModificadaMedia (4.8)0.89%—Openteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the SitePages module.
ModificadaMedia (5.4)1.1%💥 PoCOpenteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module.
ModificadaMedia (5.4)1.1%💥 PoCOpenteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module.
ModificadaAlta (8.8)0.98%—Supsystic Social Share Buttons22/7/202217/6/2026
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
ModificadaAlta (8.8)0.92%—Supsystic Social Share Buttons22/7/202217/6/2026
Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
ModificadaMedia (4.8)0.52%—Social Media Share Buttons Project Social Media Share Buttons20/7/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons plugin <= 3.8.1 at WordPress.
ModificadaCrítica (9.8)1.7%—Slickremix Feed Them Social18/7/202217/6/2026
The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a PHAR wrapper that will deserialize the data…
Orbitaley — Vulnerabilidades