Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.33% | — | Kraftplugins Mega Elements | 15/5/2024 | 17/6/2026 | The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.52% | — | Smartypantsplugins SP Project & Document Manager | 15/5/2024 | 17/6/2026 | The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user | |
| Analizada | Media (6.5) | 0.43% | — | Smartypantsplugins SP Project & Document Manager | 15/5/2024 | 17/6/2026 | The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user | |
| Aplazada | Media (6.4) | 0.46% | — | Bplugins Html5 Audio PlayerAI | 14/5/2024 | 17/6/2026 | The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.2.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.25% | — | Warfareplugins Social WarfareAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Warfare Plugins Social Warfare.This issue affects Social Warfare: from n/a through 4.4.5.1. | |
| Aplazada | Alta (8.8) | 1.6% | — | Plugins360 All-in-one Video GalleryAI | 2/5/2024 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_attachment_from_external_image_url function in all versions up to, and including, 3.6.4. This makes it possible for authenticated attackers, with contributor access and… | |
| Aplazada | Media (4.3) | 0.56% | — | Pickplugins Post GridAI | 2/5/2024 | 17/6/2026 | The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtTPGSaveSettings function in all versions up to, and including, 7.6.1. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.42% | — | Warfareplugins Social WarfareAI | 2/5/2024 | 17/6/2026 | The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialWarfare' shortcode in all versions up to, and including, 4.4.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.38% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16. | |
| Aplazada | Media (5.3) | 0.52% | — | Realbigplugins Client DashAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1. | |
| Aplazada | Alta (7.5) | 0.55% | — | Solid Plugins Solid AffiliateAI | 29/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through 1.9.1. | |
| Aplazada | Alta (7.1) | 0.18% | — | Toast Plugins Sticky AnythingAI | 29/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Sticky Anything allows Cross-Site Scripting (XSS).This issue affects Sticky Anything: from n/a through 2.1.5. | |
| Aplazada | Crítica (9.9) | 0.66% | — | Eazyplugins Eazy Plugin ManagerAI | 25/4/2024 | 17/6/2026 | Improper Authentication vulnerability in EazyPlugins Eazy Plugin Manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Eazy Plugin Manager: from n/a through 4.1.2. | |
| Aplazada | Alta (7.5) | 0.68% | — | Pickplugins Post GridAI | 24/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid.This issue affects Post Grid: from n/a through 2.2.78. | |
| Aplazada | Media (5.5) | 0.33% | — | Really-simple-plugins Really Simple SSLAI | 18/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Simple SSL: from n/a through 7.2.3. | |
| Modificada | Media (5.4) | 0.32% | — | Kraftplugins Mega Elements | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraftplugins Mega Elements allows Stored XSS.This issue affects Mega Elements: from n/a through 1.1.9. | |
| Aplazada | Media (4.3) | 0.30% | — | Verygoodplugins Fatal Error NotifyAI | 16/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Very Good Plugins Fatal Error Notify.This issue affects Fatal Error Notify: from n/a through 1.5.2. | |
| Modificada | Media (4.3) | 0.75% | 💥 PoC | Xlplugins Nextmove | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.18.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Goldplugins Before AND AfterAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Gold Plugins Before And After.This issue affects Before And After: from n/a through 3.9. | |
| Modificada | Alta (8.8) | 0.24% | — | Cleverplugins SEO Booster | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in cleverplugins.Com SEO Booster.This issue affects SEO Booster: from n/a through 3.8.9. | |
| Modificada | Media (6.1) | 0.35% | — | Ezplugins EZ Form Calculator | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Schuppenies EZ Form Calculator allows Reflected XSS.This issue affects EZ Form Calculator: from n/a through 2.14.0.3. | |
| Aplazada | Media (5.4) | 0.20% | — | Catchplugins Generate Child ThemeAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Catch Plugins Generate Child Theme.This issue affects Generate Child Theme: from n/a through 2.0. | |
| Aplazada | Media (5.4) | 0.20% | — | Quick-plugins Loan Repayment Calculator AND Application FormAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in aerin Loan Repayment Calculator and Application Form.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.4. | |
| Analizada | Media (5.4) | 17% | 💥 Exploit | Pickplugins Post Grid | 11/4/2024 | 17/6/2026 | The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts | |
| Modificada | Media (4.3) | 0.21% | — | Xlplugins Finale | 11/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0. |