Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
721 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.42% | — | Ghozylab Gallery FOR Social Photo | 18/7/2022 | 17/6/2026 | The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_duplicate_feed. This make it possible for unauthenticated attackers to duplicate existing posts or… | |
| Modificada | Media (4.3) | 0.43% | — | Supsystic Social Share Buttons | 27/6/2022 | 17/6/2026 | The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks. | |
| Modificada | Crítica (9.8) | 0.44% | — | IBM Curam Social Program Management | 20/6/2022 | 17/6/2026 | IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | |
| Modificada | Crítica (9.8) | 0.51% | — | IBM Curam Social Program Management | 20/6/2022 | 17/6/2026 | IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281. | |
| Modificada | Media (4.8) | 0.60% | — | Facebook-wall-and-social-integration Project Facebook-wall-and-social-integration | 13/6/2022 | 17/6/2026 | The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.5) | 0.53% | — | Byonepress Social Locker | 13/6/2022 | 17/6/2026 | The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (4.3) | 0.42% | — | Supsystic Social Share Buttons | 2/6/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.2 at WordPress. | |
| Modificada | Media (5.4) | 0.50% | — | Simple Social Networking Site Project Simple Social Networking Site | 24/5/2022 | 17/6/2026 | Simple Social Networking Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /sns/classes/Users.php?f=save, firstname. | |
| Modificada | Media (6.1) | 0.40% | — | Pluginmirror Social Stickers | 16/5/2022 | 17/6/2026 | The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in admin change them and lead to Stored Cross-Site Scripting issues. | |
| Modificada | Media (4.8) | 0.60% | — | Th23 Social | 16/5/2022 | 17/6/2026 | The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Alta (7.2) | 0.97% | — | Simple Social Networking Site Project Simple Social Networking Site | 13/5/2022 | 17/6/2026 | Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=. | |
| Modificada | Alta (7.2) | 0.97% | — | Simple Social Networking Site Project Simple Social Networking Site | 13/5/2022 | 17/6/2026 | Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=posts/view_post&id=. | |
| Modificada | Alta (7.2) | 0.97% | — | Simple Social Networking Site Project Simple Social Networking Site | 13/5/2022 | 17/6/2026 | Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/members/view_member.php?id=. | |
| Modificada | Media (6.5) | 0.87% | — | Simple Social Networking Site Project Simple Social Networking Site | 13/5/2022 | 17/6/2026 | Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img. | |
| Modificada | Media (4.8) | 0.60% | — | Wp-experts WP Social Buttons | 9/5/2022 | 17/6/2026 | The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8.8) | 0.83% | — | 3xsocializer Project 3xsocializer | 25/4/2022 | 17/6/2026 | SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with a low role like a subscriber or higher. | |
| Modificada | Media (4.8) | 0.60% | — | Wpdevart Social Comments | 25/4/2022 | 17/6/2026 | The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Easysocialfeed Easy Social Feed | 18/4/2022 | 17/6/2026 | The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (4.8) | 0.60% | — | Sharethis Social Media Feather | 11/4/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versions <= 2.0.4 | |
| Modificada | Media (5.4) | 0.52% | — | IBM Curam Social Program Management | 11/4/2022 | 17/6/2026 | IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 215306. | |
| Modificada | Media (4.8) | 0.60% | — | Cybernetikz Easy Social Icons | 11/4/2022 | 17/6/2026 | The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Heateor Super Socializer | 11/4/2022 | 17/6/2026 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site… | |
| Modificada | Alta (7.2) | 2.6% | — | Socialcodia Social Codia SMS | 8/4/2022 | 17/6/2026 | Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Media (4.8) | 1.1% | — | Socialcodia Social Codia SMS | 8/4/2022 | 17/6/2026 | Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field. | |
| Modificada | Alta (7.2) | 1.3% | — | Cybernetikz Easy Social Icons | 4/4/2022 | 17/6/2026 | The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability. |