Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2445 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.13% | — | Pluginsware Advanced Classifieds AND Directory PROAI | 24/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in pluginsware Advanced Classifieds & Directory Pro advanced-classifieds-and-directory-pro allows Cross Site Request Forgery.This issue affects Advanced Classifieds & Directory Pro: from n/a through <= 3.2.9. | |
| Aplazada | Media (4.3) | 0.19% | — | Spiffyplugins Spiffy CalendarAI | 24/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spiffy Calendar: from n/a through <= 5.0.7. | |
| Aplazada | Media (4.7) | 0.52% | 💥 Exploit | Plugin-planet User Submitted PostsAI | 24/12/2025 | 7/10/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Jeff Starr User Submitted Posts user-submitted-posts allows Phishing.This issue affects User Submitted Posts: from n/a through <= 20251121. | |
| Aplazada | Media (5.9) | 0.21% | — | THE Plugin Factory Google Adsense FOR Responsive Design GardAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Plugin Factory Google AdSense for Responsive Design – GARD google-adsense-for-responsive-design-gard allows DOM-Based XSS.This issue affects Google AdSense for Responsive Design – GARD: from n/a through <= 2.23. | |
| Aplazada | Media (6.4) | 0.24% | — | Membership Plugin Restrict ContentAI | 23/12/2025 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (4.3) | 0.12% | — | Pluginops Feather Login PageAI | 22/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page feather-login-page allows Cross Site Request Forgery.This issue affects Feather Login Page: from n/a through <= 1.1.7. | |
| Aplazada | Media (6.1) | 0.21% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 21/12/2025 | 17/6/2026 | The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.4) | 0.23% | — | Amazon Affiliate Lite PluginAI | 20/12/2025 | 17/6/2026 | The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Aplazada | Media (6.4) | 0.32% | — | Teclib Database Inventory PluginAI | 19/12/2025 | 17/6/2026 | pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. Prior to version 1.1.2, in certain conditions (database write access must first be obtained through another vulnerability or misconfiguration), user-controlled… | |
| Aplazada | Alta (7.2) | 0.24% | — | Bplugins Html5 Audio PlayerAI | 19/12/2025 | 17/6/2026 | The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions from 2.4.0 up to, and including, 2.5.1 via the getIcyMetadata() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Aplazada | Media (6.5) | 0.24% | — | Pickplugins Post GridAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17. | |
| Aplazada | Media (5.3) | 0.24% | — | Pickplugins Post Grid AND Gutenberg BlocksAI | 18/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23. | |
| Aplazada | Alta (8.8) | 0.35% | 💥 PoC | Kraftplugins Demo Importer PlusAI | 18/12/2025 | 17/6/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missing capability check on the Ajax::handle_request() function in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.29% | — | Fantasticplugins Woocommerce Recover Abandoned CartAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in FantasticPlugins WooCommerce Recover Abandoned Cart rac allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Recover Abandoned Cart: from n/a through <= 24.6.0. | |
| Aplazada | Alta (7.1) | 0.22% | — | Designthemes Dt-reservation-pluginAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Reservation Plugin dt-reservation-plugin allows Reflected XSS.This issue affects Reservation Plugin: from n/a through <= 1.6. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Constant Contact Plugin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.This issue affects WP Gravity Forms Constant Contact Plugin: from n/a through <= 1.1.2. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Freshdesk Plugin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5. | |
| Aplazada | Alta (7.5) | 0.35% | — | Bplugins PDF FOR Gravity FormsAIGravityforms Gravity FormsAI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Gravity Forms + Drag And Drop Template Builder pdf-for-gravity-forms allows Object Injection.This issue affects PDF for Gravity Forms + Drag And Drop Template Builder: from n/a through <= 6.5.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Bplugins Parallax SectionAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in bPlugins Parallax Section block parallax-section allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Parallax Section block: from n/a through <= 1.0.9. | |
| Aplazada | Alta (8.8) | 0.36% | — | E-plugins Hotel ListingAI | 18/12/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation.This issue affects Hotel Listing: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.2) | 0.39% | — | Silverplugins217 Custom-fields-account-registration-for-woocommerceAI | 18/12/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in silverplugins217 Custom Fields Account Registration For Woocommerce custom-fields-account-registration-for-woocommerce allows Privilege Escalation.This issue affects Custom Fields Account Registration For Woocommerce: from n/a through <= 1.2. | |
| Aplazada | Media (4.3) | 0.12% | — | Download Plugins AND Themes IN ZIP From DashboardAI | 17/12/2025 | 28/9/2026 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.6. This is due to missing or incorrect nonce validation on the download_plugin_bulk and download_theme_bulk functions. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.51% | — | Vitejs Plugin RSAI | 16/12/2025 | 17/6/2026 | @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted… | |
| Aplazada | Media (5.4) | 0.12% | — | Meks Quick Plugin DisablerAI | 16/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cross Site Request Forgery.This issue affects Meks Quick Plugin Disabler: from n/a through <= 1.0. | |
| Aplazada | Media (5.9) | 0.21% | — | Barn2 Plugins Document Library LiteAI | 16/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows DOM-Based XSS.This issue affects Document Library Lite: from n/a through <= 1.1.7. |