Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.44% | — | Custom Content Shortcode Project Custom Content Shortcode | 20/3/2023 | 17/6/2026 | The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.40% | — | Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms | 16/3/2023 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions. | |
| Modificada | Media (6.1) | 0.42% | — | SAP Content Server | 14/3/2023 | 17/6/2026 | SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can read and modify some sensitive information but cannot delete the data. | |
| Modificada | Media (6.8) | 0.92% | — | Vmware Workspace ONE Content | 28/2/2023 | 17/6/2026 | VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode. | |
| Modificada | Media (5.4) | 0.47% | — | Timed Content Project Timed Content | 21/2/2023 | 17/6/2026 | The Timed Content WordPress plugin before 2.73 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.48% | — | Croover Rich Table OF Contents | 13/2/2023 | 17/6/2026 | The Rich Table of Contents WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.55% | — | Custom-content-width Project Custom-content-width | 7/2/2023 | 17/6/2026 | A vulnerability was found in Custom-Content-Width 1.0. It has been declared as problematic. Affected by this vulnerability is the function override_content_width/register_settings of the file custom-content-width.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The complexity… | |
| Modificada | Media (5.3) | 0.73% | — | Lcweb Privatecontent | 30/1/2023 | 17/6/2026 | The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side validation in versions up to, and including, 8.4.3. This is due to the plugin checking if an IP had been blocklist via client-side scripts rather than server-side. This makes it possible for… | |
| Modificada | Crítica (9.8) | 0.88% | — | Contentstudio | 27/1/2023 | 17/6/2026 | The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to execute functions intended for use by users with proper API keys. | |
| Modificada | Media (5.3) | 0.91% | — | Contentstudio | 27/1/2023 | 17/6/2026 | The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.5. This could allow unauthenticated attackers to obtain a nonce needed for the creation of posts. | |
| Modificada | Media (6.5) | 0.95% | — | Contentstudio | 27/1/2023 | 17/6/2026 | The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to obtain the blog metadata (via the function cstu_get_metadata) that includes the plugin's… | |
| Modificada | Media (5.4) | 0.47% | — | Wpsc-plugin Structured Content | 23/1/2023 | 17/6/2026 | The Structured Content WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.4) | 0.47% | — | Code-atlantic Content Control | 23/1/2023 | 17/6/2026 | The Content Control WordPress plugin before 1.1.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such as… | |
| Modificada | Crítica (9.8) | 0.75% | — | Seltmann-webdesign Content Management System | 19/1/2023 | 17/6/2026 | Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php. | |
| Modificada | Crítica (9.8) | 0.61% | — | Contentmap Project Contentmap | 18/1/2023 | 17/6/2026 | A vulnerability was found in AlexRed contentmap. It has been rated as critical. Affected by this issue is the function Load of the file contentmap.php. The manipulation of the argument contentid leads to sql injection. The name of the patch is dd265d23ff4abac97422835002c6a47f45ae2a66. It is recommended to apply a… | |
| Modificada | Media (5.4) | 0.57% | — | Dublue Table OF Contents Plus | 9/1/2023 | 17/6/2026 | The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Media (6.1) | 0.59% | — | EEA Eionet Content Registry | 15/12/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in European Environment Agency eionet.contreg. This issue affects some unknown processing. The manipulation of the argument searchTag/resourceUri leads to cross site scripting. The attack may be initiated remotely. Upgrading to version… | |
| Modificada | Media (6.1) | 0.51% | — | Collective.dms.basecontent Project Collective.dms.basecontent | 14/12/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in collective.dms.basecontent up to 1.6. This issue affects the function renderCell of the file src/collective/dms/basecontent/browser/column.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to… | |
| Modificada | Alta (8.8) | 0.74% | — | IBM Content Navigator | 7/12/2022 | 17/6/2026 | IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins and execute code. IBM X-Force ID: 238805. | |
| Modificada | Media (4.8) | 0.45% | — | Rockcontent Rock Convert | 3/11/2022 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress. | |
| Modificada | Alta (8.8) | 0.32% | — | Keywordrush Content EGG | 3/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress. | |
| Modificada | Media (4.8) | 0.53% | — | Rockcontent Rock Convert | 31/10/2022 | 17/6/2026 | The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.54% | — | Rockcontent Rock Convert | 31/10/2022 | 17/6/2026 | The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (8.8) | 0.59% | — | Xjyunjing Yunjing Content Management System | 31/10/2022 | 17/6/2026 | A vulnerability classified as critical was found in Yunjing CMS. This vulnerability affects unknown code of the file /index/user/upload_img.html. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (7.8) | 0.22% | — | Sony Content Transfer | 24/10/2022 | 17/6/2026 | Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. |