Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

721 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.42%—Ghozylab Gallery FOR Social Photo18/7/202217/6/2026
The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_duplicate_feed. This make it possible for unauthenticated attackers to duplicate existing posts or…
ModificadaMedia (4.3)0.43%—Supsystic Social Share Buttons27/6/202217/6/2026
The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks.
ModificadaCrítica (9.8)0.44%—IBM Curam Social Program Management20/6/202217/6/2026
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
ModificadaCrítica (9.8)0.51%—IBM Curam Social Program Management20/6/202217/6/2026
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.
ModificadaMedia (4.8)0.60%—Facebook-wall-and-social-integration Project Facebook-wall-and-social-integration13/6/202217/6/2026
The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (6.5)0.53%—Byonepress Social Locker13/6/202217/6/2026
The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (4.3)0.42%—Supsystic Social Share Buttons2/6/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.2 at WordPress.
ModificadaMedia (5.4)0.50%—Simple Social Networking Site Project Simple Social Networking Site24/5/202217/6/2026
Simple Social Networking Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /sns/classes/Users.php?f=save, firstname.
ModificadaMedia (6.1)0.40%—Pluginmirror Social Stickers16/5/202217/6/2026
The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in admin change them and lead to Stored Cross-Site Scripting issues.
ModificadaMedia (4.8)0.60%—Th23 Social16/5/202217/6/2026
The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaAlta (7.2)0.97%—Simple Social Networking Site Project Simple Social Networking Site13/5/202217/6/2026
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=.
ModificadaAlta (7.2)0.97%—Simple Social Networking Site Project Simple Social Networking Site13/5/202217/6/2026
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=posts/view_post&id=.
ModificadaAlta (7.2)0.97%—Simple Social Networking Site Project Simple Social Networking Site13/5/202217/6/2026
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/members/view_member.php?id=.
ModificadaMedia (6.5)0.87%—Simple Social Networking Site Project Simple Social Networking Site13/5/202217/6/2026
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img.
ModificadaMedia (4.8)0.60%—Wp-experts WP Social Buttons9/5/202217/6/2026
The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (8.8)0.83%—3xsocializer Project 3xsocializer25/4/202217/6/2026
SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with a low role like a subscriber or higher.
ModificadaMedia (4.8)0.60%—Wpdevart Social Comments25/4/202217/6/2026
The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (6.1)2.9%💥 ExploitEasysocialfeed Easy Social Feed18/4/202217/6/2026
The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues
ModificadaMedia (4.8)0.60%—Sharethis Social Media Feather11/4/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versions <= 2.0.4
ModificadaMedia (5.4)0.52%—IBM Curam Social Program Management11/4/202217/6/2026
IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 215306.
ModificadaMedia (4.8)0.60%—Cybernetikz Easy Social Icons11/4/202217/6/2026
The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.1)1.9%💥 ExploitHeateor Super Socializer11/4/202217/6/2026
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site…
ModificadaAlta (7.2)2.6%—Socialcodia Social Codia SMS8/4/202217/6/2026
Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (4.8)1.1%—Socialcodia Social Codia SMS8/4/202217/6/2026
Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.
ModificadaAlta (7.2)1.3%—Cybernetikz Easy Social Icons4/4/202217/6/2026
The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.
Orbitaley — Vulnerabilidades