Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.29% | — | Erwinwolff Wordpress Activity-o-meter | 7/3/2025 | 17/6/2026 | The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins. | |
| Aplazada | Alta (8.8) | 0.46% | — | Wordpress Awesome Import Export Awesome Import ExportAI | 5/3/2025 | 17/6/2026 | The WordPress Awesome Import & Export Plugin - Import & Export WordPress Data plugin for WordPress is vulnerable arbitrary SQL Execution and privilege escalation due to a missing capability check on the renderImport() function in all versions up to, and including, 4.1.1. This makes it possible for authenticated… | |
| Analizada | Media (4.6) | 0.31% | — | Teampasswordmanager Team Password Manager | 4/3/2025 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page. | |
| Aplazada | Alta (7.2) | 0.70% | — | Beaver Builder Wordpress AssistantAI | 3/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1. | |
| Aplazada | Alta (7.1) | 0.39% | — | Wordquest Guten Free OptionsAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tony Hayes Guten Free Options guten-free-options allows Reflected XSS.This issue affects Guten Free Options: from n/a through <= 0.9.7. | |
| Analizada | Media (6.5) | 0.28% | — | Wordplus Better Messages | 1/3/2025 | 17/6/2026 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.4 via the 'nice_links'. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Analizada | Alta (7.5) | 0.50% | — | Wordplus Better Messages | 1/3/2025 | 17/6/2026 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the 'bp-better-messages' directory. This makes it possible for unauthenticated attackers to extract… | |
| Aplazada | Alta (8.8) | 0.77% | — | Surveyjs Drag AND Drop Wordpress Form BuilderAI | 1/3/2025 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary file deletion due to a missing capability check on the callback function of the SurveyJS_DeleteFile class in all versions up to, and including, 1.12.17. This… | |
| Aplazada | Media (6.5) | 0.28% | — | Webandprint AR FOR WordpressAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webandprint AR For WordPress ar-for-wordpress allows DOM-Based XSS.This issue affects AR For WordPress: from n/a through <= 7.7. | |
| Analizada | Media (4.3) | 0.17% | — | Iptanus Wordpress File Upload | 25/2/2025 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the 'wfu_file_details' function. This makes it possible for unauthenticated attackers to modify user data details associated… | |
| Aplazada | Media (4.3) | 0.16% | — | Will Anderson Minimum-password-strengthAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Will Anderson Minimum Password Strength minimum-password-strength allows Cross Site Request Forgery.This issue affects Minimum Password Strength: from n/a through <= 1.2.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Aaron D. Campbell Google-maps-for-wordpressAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aaron D. Campbell Google Maps for WordPress google-maps-for-wordpress allows DOM-Based XSS.This issue affects Google Maps for WordPress: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.2) | 0.26% | — | Roboform Password ManagerAI | 17/2/2025 | 17/6/2026 | Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with access to a device where the application is installed to bypass the lock screen and obtain sensitive information. | |
| Aplazada | Alta (7.1) | 0.15% | — | What3words Address FieldAI | 16/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in what3words what3words Address Field 3-word-address-validation-field allows Stored XSS.This issue affects what3words Address Field: from n/a through <= 4.0.15. | |
| Aplazada | Media (6.5) | 0.23% | — | Upcasted AWS S3 FOR Wordpress PluginAI | 16/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in upcasted AWS S3 for WordPress Plugin – Upcasted upcasted-s3-offload allows Stored XSS.This issue affects AWS S3 for WordPress Plugin – Upcasted: from n/a through <= 3.0.3. | |
| Aplazada | Alta (7.1) | 0.31% | — | Rusalex Wordpress-to-candidate FOR Salesforce CRMAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RusAlex WordPress-to-candidate for Salesforce CRM salesforce-wordpress-to-candidate allows Reflected XSS.This issue affects WordPress-to-candidate for Salesforce CRM: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.28% | — | Cantonbolo Wordpress TaobaokeAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CantonBolo WordPress 淘宝客插件 taobaoke allows Reflected XSS.This issue affects WordPress 淘宝客插件: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.1) | 0.28% | — | Arash Safari Qmean Wordpress DID YOU MeanAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arash Safari QMean – WordPress Did You Mean qmean allows Reflected XSS.This issue affects QMean – WordPress Did You Mean: from n/a through <= 2.0. | |
| Aplazada | Alta (7.1) | 0.15% | — | Kunal Shivale Global Meta Keyword AND DescriptionAI | 13/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kunal Shivale Global Meta Keyword & Description global-meta-keyword-and-description allows Stored XSS.This issue affects Global Meta Keyword & Description: from n/a through <= 2.3. | |
| Aplazada | Alta (7.1) | 0.15% | — | Blackus3r WP Keyword MonitorAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in blackus3r WP Keyword Monitor wp-keyword-monitor allows Cross Site Request Forgery.This issue affects WP Keyword Monitor: from n/a through <= 1.0.5. | |
| Analizada | Media (6.1) | 0.58% | 💥 Exploit | Wordquest Guten Free Options | 7/2/2025 | 17/6/2026 | The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Alta (7.2) | 0.68% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 3/2/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.5. | |
| Aplazada | Alta (7.1) | 0.33% | — | Abinav Thakuri Wordpress SignatureAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abinav Thakuri WordPress Signature wordpress-signature allows Reflected XSS.This issue affects WordPress Signature: from n/a through <= 0.1. | |
| Aplazada | Alta (7.1) | 0.17% | — | Chegevara29 Tags TO KeywordsAI | 3/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CheGevara29 Tags to Keywords tags-to-meta-keywords allows Stored XSS.This issue affects Tags to Keywords: from n/a through <= 1.0.1. | |
| Analizada | Media (5.4) | 0.31% | — | Wordplus Better Messages | 1/2/2025 | 17/6/2026 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'better_messages_live_chat_button' shortcode in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output… |