Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2472 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.20% | — | Johnny Post List Featured Image Post List Featured ImageAI | 27/10/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johnny Post List Featured Image post-list-featured-image allows Stored XSS.This issue affects Post List Featured Image: from n/a through <= 0.5.9. | |
| Aplazada | Media (6.4) | 0.23% | — | WP Force Images DownloadAI | 22/10/2025 | 17/6/2026 | The WP-Force Images Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpfid' shortcode in all versions up to, and including, 1.8. This is due to insufficient input sanitization and output escaping on the 'class' attribute. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.9) | 0.45% | — | Wikimedia Mediawiki Imagerating ExtensionAI | 18/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - ImageRating Extension allows Stored XSS.This issue affects Mediawiki - ImageRating Extension: from master before 1.39. | |
| Aplazada | Media (5.4) | 0.31% | — | Shortpixel Image OptimizerAI | 18/10/2025 | 17/6/2026 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authenticated attackers,… | |
| Modificada | Alta (7.5) | 0.81% | — | Imagemagick | 17/10/2025 | 17/6/2026 | ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by… | |
| Aplazada | Media (4.3) | 0.24% | — | Quick Featured ImagesAI | 15/10/2025 | 17/6/2026 | The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 13.7.2 via the qfi_set_thumbnail and qfi_delete_thumbnail AJAX actions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.9) | 0.64% | — | Grafana Image RendererAI | 9/10/2025 | 17/6/2026 | Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to save a shared object to an arbitrary location that is then loaded by the Chromium… | |
| Aplazada | Media (5.4) | 0.19% | — | Majestic Before After ImageAI | 4/10/2025 | 17/6/2026 | The Majestic Before After Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_label' and 'after_label' parameters in versions less than, or equal to, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.12% | — | Acronis True ImageAIAcronis True Image FOR SandiskAIAcronis True Image FOR Western DigitalAIAcronis True Image OEMAI | 30/9/2025 | 17/6/2026 | Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) before build 42389, Acronis True Image for SanDisk (macOS) before build 42198, Acronis True Image for Western Digital (macOS) before build 42197, Acronis True Image OEM (macOS) before… | |
| Aplazada | Alta (7.3) | 0.18% | — | Acronis True ImageAIAcronis True Image FOR Western DigitalAIAcronis True Image FOR SandiskAIAcronis True Image OEMAI | 30/9/2025 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42386, Acronis True Image for Western Digital (Windows) before build 42636, Acronis True Image for SanDisk (Windows) before build 42679, Acronis True Image OEM (Windows) before… | |
| Aplazada | Media (4.9) | 0.33% | — | Fifu Featured Image From URLAI | 26/9/2025 | 17/6/2026 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_featured_image() function in all versions up to, and including, 5.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (5.9) | 0.22% | — | MAT Category Featured ImagesAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mat Category Featured Images category-featured-images allows Stored XSS.This issue affects Category Featured Images: from n/a through <= 1.1.8. | |
| Aplazada | Media (6.5) | 0.20% | — | Image-editor-by-pixoAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ickata Image Editor by Pixo image-editor-by-pixo allows DOM-Based XSS.This issue affects Image Editor by Pixo: from n/a through <= 2.3.8. | |
| Aplazada | Media (5.3) | 0.75% | 💥 Exploit | Iberezansky 3D Flipbook PDF Flipbook Viewer Flipbook Image GalleryAI | 22/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in iberezansky 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery interactive-3d-flipbook-powered-physics-engine allows Retrieve Embedded Sensitive Data.This issue affects 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery: from n/a through… | |
| Aplazada | Media (6.5) | 0.21% | — | Wpo-hr NGG Smart Image SearchAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpo-HR NGG Smart Image Search ngg-smart-image-search allows Stored XSS.This issue affects NGG Smart Image Search: from n/a through <= 3.4.3. | |
| Aplazada | Media (5.3) | 0.36% | — | Blocksera Image Hover Effects Addon FOR ElementorAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Blocksera Image Hover Effects – Elementor Addon image-hover-effects-addon-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Hover Effects – Elementor Addon: from n/a through <= 1.4.4. | |
| Aplazada | Media (5.9) | 0.23% | — | CK Macleod Category Featured Images ExtendedAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CK MacLeod Category Featured Images Extended category-featured-images-extended allows Stored XSS.This issue affects Category Featured Images Extended: from n/a through <= 1.52. | |
| Aplazada | Crítica (9.6) | 0.17% | — | Yonisink Custom Post Type ImagesAI | 22/9/2025 | 1/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in yonisink Custom Post Type Images custom-post-types-image allows Code Injection.This issue affects Custom Post Type Images: from n/a through <= 0.5. | |
| Aplazada | Media (6.4) | 0.20% | — | Auto Save Remote Images DraftsAI | 10/9/2025 | 17/6/2026 | The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 via the fetch_images() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations… | |
| Modificada | Crítica (9.8) | 0.29% | — | Imagemagick | 5/9/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum +… | |
| Aplazada | Media (6.5) | 0.21% | — | Wpbean WPB Image WidgetAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBean WPB Image Widget wpb-image-widget allows Stored XSS.This issue affects WPB Image Widget: from n/a through <= 1.1. | |
| Aplazada | Crítica (9.1) | 0.34% | — | Creedallyinc Bulk Featured ImageAI | 5/9/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Upload a Web Shell to a Web Server.This issue affects Bulk Featured Image: from n/a through <= 1.2.4. | |
| Aplazada | Alta (8.7) | 0.42% | — | Changing Clinic Image SystemAI | 29/8/2025 | 17/6/2026 | Clinic Image System developed by Changing has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Changing Clinic Image SystemAI | 29/8/2025 | 17/6/2026 | Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to log into the system using administrator credentials embedded in the source code. | |
| Aplazada | Alta (7.1) | 0.13% | — | Kasonzhao SEO FOR ImagesAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in kasonzhao SEO For Images seo-for-images allows Stored XSS.This issue affects SEO For Images: from n/a through <= 1.0.0. |