Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2671▼ 680 respecto a la semana anterior
Críticas / altas1271▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)230▼ 272 respecto a la semana anterior
–

721 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)2.2%💥 ExploitHeateor Sassy Social Share28/3/202217/6/2026
The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (6.5)0.53%—Nextscripts Social Networks Auto Poster1/2/202217/6/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack
ModificadaMedia (6.1)1.3%—Nextscripts Social Networks Auto Poster1/2/202217/6/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue
ModificadaMedia (5.4)1.0%💥 ExploitSmashballoon Smash Balloon Social Post Feed17/1/202217/6/2026
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
ModificadaMedia (6.1)0.80%—10websocial10/1/202217/6/2026
The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any logged in users
ModificadaMedia (6.1)1.4%💥 ExploitAdenion Blog2social21/12/202117/6/2026
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (5.4)0.68%—Smashballoon Smash Balloon Social Post Feed29/11/202117/6/2026
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.
ModificadaMedia (4.8)0.57%—Acurax Floating Social Media Icon26/11/202117/6/2026
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin (versions <= 4.3.5) Social Media Configuration form. Requires high role user like admin.
ModificadaMedia (6.1)0.87%—Nextscripts Social Networks Auto Poster1/11/202117/6/2026
The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to load the page in $_GET['page'] along with malicious JavaScript…
ModificadaAlta (8.8)2.0%—Heateor Sassy Social Share21/10/202117/6/2026
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the ~/admin/class-sassy-social-share-admin.php file. This can be…
ModificadaMedia (4.8)0.62%—Wpbrigade Simple Social Buttons11/10/202117/6/2026
The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.1)1.3%—Smashballoon Smash Balloon Social Post Feed13/9/202117/6/2026
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored…
ModificadaMedia (6.1)2.3%💥 ExploitCybernetikz Easy Social Icons2/9/202117/6/2026
The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.
ModificadaMedia (5.4)0.62%—Wpbrigade Simple Social Media Share Buttons23/8/202117/6/2026
The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size parameters of its SSB shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (6.1)0.41%—Social Tape Project Social Tape16/8/202117/6/2026
The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a stored Cross-Site Scripting issue via a CSRF attack
ModificadaMedia (5.4)0.68%—Cm-wp Social Slider Widget5/4/202117/6/2026
The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized
ModificadaAlta (8.8)1.3%—Accesspressthemes Accesspress Social Icons18/3/202117/6/2026
Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.
ModificadaAlta (8.8)1.5%—Adenion Blog2social18/3/202117/6/2026
Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands.
ModificadaCrítica (9.8)0.87%—Chatter-social Creeper4/1/202117/6/2026
Creeper is an experimental dynamic, interpreted language. The binary release of Creeper Interpreter 1.1.3 contains potential malware. The compromised binary release was available for a few hours between December 26, 2020 at 3:22 PM EST to December 26, 2020 at 11:00 PM EST. If you used the source code, you are **NOT**…
ModificadaAlta (8.8)0.53%—IBM Curam Social Program Management4/1/202117/6/2026
IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191942.
ModificadaAlta (7.4)0.65%—Nextcloud Social19/11/202017/6/2026
Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.
ModificadaMedia (5.3)1.0%—Nextcloud Social19/11/202017/6/2026
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
ModificadaCrítica (9.8)1.6%—Jomsocial4/11/202017/6/2026
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
ModificadaMedia (6.5)1.4%—IBM Curam Social Program Management12/10/202017/6/2026
An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could result in a denial of service. IBM X-Force ID: 189159.
Orbitaley — Vulnerabilidades