Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.48% | — | Spiffyplugins Spiffy Calendar | 27/2/2024 | 17/6/2026 | The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+. | |
| Analizada | Media (6.1) | 0.23% | — | Verygoodplugins Fatal Error Notify | 27/2/2024 | 17/6/2026 | The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber to call it and spam the admin email address with error messages. The issue is also exploitable via CSRF | |
| Modificada | Alta (7.2) | 0.60% | — | Bplugins Icons Font Loader | 26/2/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4. | |
| Modificada | Media (5.3) | 0.48% | — | Pluginsandsnippets Simple Page Access Restriction | 8/2/2024 | 17/6/2026 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content. | |
| Modificada | Media (5.4) | 0.34% | — | Coolplugins Timeline Widget FOR Elementor | 7/2/2024 | 17/6/2026 | The Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image URLs in the plugin's timeline widget in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied… | |
| Analizada | Alta (7.5) | 0.95% | — | Coolplugins Cryptocurrency Widgets | 5/2/2024 | 17/6/2026 | The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Media (5.4) | 0.61% | — | Richplugins Plugin FOR Google Reviews | 5/2/2024 | 17/6/2026 | This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'place_id' attribute. This makes it possible for authenticated attackers with contributor-level and above… | |
| Modificada | Media (5.4) | 0.31% | — | Fivestarplugins Five Star Restaurant Menu | 5/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five Star Restaurant Reviews: from n/a through 2.3.5. | |
| Modificada | Media (5.4) | 0.33% | — | Pickplugins Related Post | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This issue affects Related Post: from n/a through 2.0.53. | |
| Modificada | Media (5.4) | 0.32% | — | Pwrplugins Powerfolio | 31/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PWR Plugins Portfolio & Image Gallery for WordPress | PowerFolio allows Stored XSS.This issue affects Portfolio & Image Gallery for WordPress | PowerFolio: from n/a through 3.1. | |
| Modificada | Media (6.1) | 0.33% | — | Bplugins PDF Poster | 31/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins PDF Poster – PDF Embedder Plugin for WordPress allows Reflected XSS.This issue affects PDF Poster – PDF Embedder Plugin for WordPress: from n/a through 2.1.17. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | Bplugins Html5 Video Player | 30/1/2024 | 17/6/2026 | The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Warfareplugins Social Warfare | 17/1/2024 | 17/6/2026 | The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server. | |
| Modificada | Media (5.4) | 0.34% | — | Pickplugins Post Grid Combo | 11/1/2024 | 17/6/2026 | The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access… | |
| Modificada | Media (5.4) | 0.44% | — | Wp-plugins Video Popup | 11/1/2024 | 17/6/2026 | The Video PopUp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'video_popup' shortcode in versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Modificada | Alta (8.8) | 0.32% | — | Aviplugins WP Register Profile With Shortcode | 11/1/2024 | 17/6/2026 | The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due to missing or incorrect nonce validation on the update_password_validate function. This makes it possible for unauthenticated attackers to reset a user's password… | |
| Modificada | Alta (8.8) | 0.54% | — | Coolplugins Events Shortcodes FOR THE Events Calendar | 8/1/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events Shortcodes For The Events Calendar: from n/a through 2.3.1. | |
| Modificada | Media (4.8) | 0.32% | — | Really-simple-plugins Complianz | 4/1/2024 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions… | |
| Modificada | Media (5.4) | 0.40% | — | Fooplugins Foogallery | 3/1/2024 | 17/6/2026 | The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for contributors and above to inject arbitrary web… | |
| Modificada | Media (5.4) | 0.53% | — | Bplugins Html5 Video Player | 1/1/2024 | 17/6/2026 | The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users… | |
| Modificada | Alta (8.1) | 0.48% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 31/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes.This issue affects Recipe Maker For Your Food Blog from Zip Recipes: from n/a through 8.1.0. | |
| Modificada | Alta (8.8) | 0.22% | — | Brightplugins Block IPS FOR Gravity Forms | 29/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bright Plugins Block IPs for Gravity Forms.This issue affects Block IPs for Gravity Forms: from n/a through 1.0.1. | |
| Modificada | Media (4.8) | 0.34% | — | Gingerplugins Sticky Chat Widget | 29/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ginger Plugins Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button allows Stored XSS.This issue affects Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call… | |
| Modificada | Alta (8.8) | 0.53% | — | Oplugins Booking Manager | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop, oplugins Booking Manager.This issue affects Booking Manager: from n/a through 2.1.5. | |
| Modificada | Media (4.8) | 0.34% | — | Quick-plugins Loan Repayment Calculator AND Application Form | 21/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aerin Loan Repayment Calculator and Application Form allows Stored XSS.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.3. |