Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2671▼ 680 respecto a la semana anterior
Críticas / altas1271▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)230▼ 272 respecto a la semana anterior
721 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Heateor Sassy Social Share | 28/3/2022 | 17/6/2026 | The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue. | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (6.5) | 0.53% | — | Nextscripts Social Networks Auto Poster | 1/2/2022 | 17/6/2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack | |
| Modificada | Media (6.1) | 1.3% | — | Nextscripts Social Networks Auto Poster | 1/2/2022 | 17/6/2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue | |
| Modificada | Media (5.4) | 1.0% | 💥 Exploit | Smashballoon Smash Balloon Social Post Feed | 17/1/2022 | 17/6/2026 | The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page. | |
| Modificada | Media (6.1) | 0.80% | — | 10websocial | 10/1/2022 | 17/6/2026 | The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any logged in users | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Adenion Blog2social | 21/12/2021 | 17/6/2026 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.4) | 0.68% | — | Smashballoon Smash Balloon Social Post Feed | 29/11/2021 | 17/6/2026 | The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages. | |
| Modificada | Media (4.8) | 0.57% | — | Acurax Floating Social Media Icon | 26/11/2021 | 17/6/2026 | Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin (versions <= 4.3.5) Social Media Configuration form. Requires high role user like admin. | |
| Modificada | Media (6.1) | 0.87% | — | Nextscripts Social Networks Auto Poster | 1/11/2021 | 17/6/2026 | The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to load the page in $_GET['page'] along with malicious JavaScript… | |
| Modificada | Alta (8.8) | 2.0% | — | Heateor Sassy Social Share | 21/10/2021 | 17/6/2026 | Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the ~/admin/class-sassy-social-share-admin.php file. This can be… | |
| Modificada | Media (4.8) | 0.62% | — | Wpbrigade Simple Social Buttons | 11/10/2021 | 17/6/2026 | The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (6.1) | 1.3% | — | Smashballoon Smash Balloon Social Post Feed | 13/9/2021 | 17/6/2026 | The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored… | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Cybernetikz Easy Social Icons | 2/9/2021 | 17/6/2026 | The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path. | |
| Modificada | Media (5.4) | 0.62% | — | Wpbrigade Simple Social Media Share Buttons | 23/8/2021 | 17/6/2026 | The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size parameters of its SSB shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.1) | 0.41% | — | Social Tape Project Social Tape | 16/8/2021 | 17/6/2026 | The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a stored Cross-Site Scripting issue via a CSRF attack | |
| Modificada | Media (5.4) | 0.68% | — | Cm-wp Social Slider Widget | 5/4/2021 | 17/6/2026 | The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized | |
| Modificada | Alta (8.8) | 1.3% | — | Accesspressthemes Accesspress Social Icons | 18/3/2021 | 17/6/2026 | Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections. | |
| Modificada | Alta (8.8) | 1.5% | — | Adenion Blog2social | 18/3/2021 | 17/6/2026 | Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands. | |
| Modificada | Crítica (9.8) | 0.87% | — | Chatter-social Creeper | 4/1/2021 | 17/6/2026 | Creeper is an experimental dynamic, interpreted language. The binary release of Creeper Interpreter 1.1.3 contains potential malware. The compromised binary release was available for a few hours between December 26, 2020 at 3:22 PM EST to December 26, 2020 at 11:00 PM EST. If you used the source code, you are **NOT**… | |
| Modificada | Alta (8.8) | 0.53% | — | IBM Curam Social Program Management | 4/1/2021 | 17/6/2026 | IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191942. | |
| Modificada | Alta (7.4) | 0.65% | — | Nextcloud Social | 19/11/2020 | 17/6/2026 | Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack. | |
| Modificada | Media (5.3) | 1.0% | — | Nextcloud Social | 19/11/2020 | 17/6/2026 | Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user. | |
| Modificada | Crítica (9.8) | 1.6% | — | Jomsocial | 4/11/2020 | 17/6/2026 | JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile. | |
| Modificada | Media (6.5) | 1.4% | — | IBM Curam Social Program Management | 12/10/2020 | 17/6/2026 | An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could result in a denial of service. IBM X-Force ID: 189159. |