Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1807 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.46% | — | Uipress LiteAI | 7/3/2025 | 17/6/2026 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the uip_save_form_as_option() function in all versions up to, and including, 3.5.04. This makes it… | |
| Aplazada | Alta (7.1) | 0.39% | — | Pillardev Easy Automatic Newsletter LiteAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PillarDev Easy Automatic Newsletter Lite easy-automatic-newsletter allows Reflected XSS.This issue affects Easy Automatic Newsletter Lite: from n/a through <= 3.2.0. | |
| Aplazada | Media (6.5) | 0.35% | — | Digitalzoomstudio DZS Ajaxer LiteAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio DZS Ajaxer Lite dzs-ajaxer-lite-dynamic-page-load allows Stored XSS.This issue affects DZS Ajaxer Lite: from n/a through <= 1.04. | |
| Aplazada | Alta (7.1) | 0.28% | — | Moallemi Google TransliterationAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moallemi Google Transliteration google-transliteration allows Reflected XSS.This issue affects Google Transliteration: from n/a through <= 1.7.2. | |
| Modificada | Media (4.3) | 0.33% | — | Uncodethemes Ultra Addons Lite FOR Elementor | 28/2/2025 | 17/6/2026 | The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.8 via the 'ut_elementor' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (6.5) | 0.26% | — | Ghozylab Easy Contact Form LiteAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Easy Contact Form Lite contact-form-lite allows Stored XSS.This issue affects Easy Contact Form Lite : from n/a through <= 1.1.25. | |
| Aplazada | Media (6.5) | 0.29% | — | Ghozylab Popup BuilderAIGhozylab Easy-notify-liteAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder easy-notify-lite allows Stored XSS.This issue affects Popup Builder: from n/a through <= 1.1.33. | |
| Aplazada | Media (6.5) | 0.34% | — | Appsbd Vitepos LiteAI | 22/2/2025 | 17/6/2026 | Missing Authorization vulnerability in appsbd Vitepos vitepos-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vitepos: from n/a through <= 3.1.3. | |
| Analizada | Alta (7.5) | 0.60% | — | Pixelite Events Manager | 21/2/2025 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (5.3) | 0.68% | — | Litespeedtech LsquicAI | 20/2/2025 | 17/6/2026 | A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2.0 allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). This is caused by XXH32 usage. | |
| Aplazada | Media (6.5) | 0.23% | — | Awsm.in Drivr Lite Google Drive PluginAI | 18/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Drivr Lite – Google Drive Plugin allows Stored XSS. This issue affects Drivr Lite – Google Drive Plugin: from n/a through 1.0.1. | |
| Modificada | Media (5.3) | 0.42% | — | Byconsole Wooodt Lite | 18/2/2025 | 17/6/2026 | The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.5.1. This is due the /inc/bycwooodt_get_all_orders.php file being publicly accessible and generating a publicly visible error message. This makes it… | |
| Analizada | Alta (7.1) | 0.57% | 💥 Exploit | Gualdoni Tube Video ADS Lite | 17/2/2025 | 17/6/2026 | The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (5.9) | 0.22% | — | Elfsight Yottie-liteAI | 13/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Yottie Lite yottie-lite allows Stored XSS.This issue affects Elfsight Yottie Lite: from n/a through <= 1.3.3. | |
| Aplazada | Crítica (9.5) | 0.86% | — | IBL Software Engineering Visual WeatherAIIBL Software Engineering NamisAIIBL Software Engineering Aero WeatherAIIBL Software Engineering Satellite WeatherAI | 7/2/2025 | 17/6/2026 | A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product Delivery Service (PDS) component in specific server configurations where the PDS pipeline utilizes the IPDS pipeline… | |
| Analizada | Media (6.1) | 0.59% | 💥 Exploit | Dtelepathy Slidedeck 1 Lite Content Slider | 31/1/2025 | 17/6/2026 | The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.4) | 0.40% | — | Divi Torque LiteAI | 29/1/2025 | 17/6/2026 | The Divi Torque Lite – Best Divi Addon, Extensions, Modules & Social Modules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Aplazada | Media (6.5) | 0.32% | — | Baidu LiteAI | 27/1/2025 | 17/6/2026 | An issue in Beijing Baidu Netcom Science & Technology Co Ltd Baidu Lite app (iOS version) 6.40.0 allows attackers to access user information via supplying a crafted link. | |
| Analizada | Media (4.8) | 0.30% | — | Wptriggers WP Triggers Lite | 27/1/2025 | 17/6/2026 | The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Analizada | Alta (7.1) | 0.57% | 💥 Exploit | Wptriggers WP Triggers Lite | 27/1/2025 | 17/6/2026 | The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.2) | 0.72% | — | Custom Product Tabs LiteAI | 25/1/2025 | 17/6/2026 | The Custom Product Tabs Lite for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.0 via deserialization of untrusted input from the 'frs_woo_product_tabs' parameter. This makes it possible for authenticated attackers, with Shop Manager-level access and… | |
| Aplazada | Media (5.4) | 0.19% | — | Wow-company Side Menu LiteAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite side-menu-lite allows Cross Site Request Forgery.This issue affects Side Menu Lite: from n/a through <= 5.3.1. | |
| Aplazada | Media (5.9) | 0.35% | — | Themeisle AI Chatbot FOR Wordpress Hyve LiteAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Stored XSS.This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through <= 1.2.2. | |
| Aplazada | Alta (7.1) | 0.39% | — | Markugwuanyi Contentoptin LiteAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in markugwuanyi ContentOptin Lite contentoptin allows Reflected XSS.This issue affects ContentOptin Lite: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Roninwp FAT Event LiteAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Event Lite fat-event-lite allows Stored XSS.This issue affects FAT Event Lite: from n/a through <= 1.1. |