Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
723 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.26% | — | Web-settler Layer Slider | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions. | |
| Modificada | Media (4.8) | 0.42% | — | Qumos Mojoplug Slide Panel | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Qumos MojoPlug Slide Panel plugin <= 1.1.2 versions. | |
| Modificada | Alta (8.8) | 2.5% | — | Themepunch Slider Revolution | 19/6/2023 | 17/6/2026 | The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations. | |
| Modificada | Media (5.4) | 0.44% | — | Slideonline Project Sideonline | 19/6/2023 | 17/6/2026 | The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Team Circle Image Slider With Lightbox | 9/6/2023 | 17/6/2026 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Photo Gallery Slideshow & Masonry Tiled Gallery | 9/6/2023 | 17/6/2026 | The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Wordpress Vertical Image Slider | 9/6/2023 | 17/6/2026 | The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (4.3) | 0.71% | — | 2joomla 2J Slideshow | 7/6/2023 | 17/6/2026 | The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'twoj_slideshow_setup' function called via the wp_ajax_twoj_slideshow_setup AJAX action in versions up to, and including, 1.3.31. This makes it possible for authenticated attackers (Subscriber, or above… | |
| Modificada | Crítica (9.8) | 0.67% | — | Joommasters JMS Slider | 5/6/2023 | 17/6/2026 | PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php. | |
| Modificada | Alta (8.8) | 0.26% | — | Codeixer Product Gallery Slider FOR Woocommerce | 29/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Codeixer Product Gallery Slider for WooCommerce plugin <= 2.2.8 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | WP Tabs Slides Project WP Tabs Slides | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Abdul Ibad WP Tabs Slides plugin <= 2.0.3 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Ljapps WP Airbnb Review Slider | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LJ Apps WP Airbnb Review Slider plugin <= 3.2 versions. | |
| Modificada | Media (6.1) | 0.61% | — | I13websolution Video Carousel Slider With Lightbox | 16/5/2023 | 17/6/2026 | The video carousel slider with lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (6.1) | 0.48% | — | I13websolution Thumbnail Carousel Slider | 15/5/2023 | 17/6/2026 | The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting vulnerability which could be used against high privilege users such as admin. | |
| Modificada | Media (4.8) | 0.37% | — | Gopiplus Tiny Carousel Horizontal Slider Plus | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Tiny carousel horizontal slider plus plugin <= 3.2 versions. | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Full Width Banner Slider WP | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Full Width Banner Slider Wp plugin <= 1.1.7 versions. | |
| Modificada | Media (5.4) | 0.37% | — | Wpmart Team Member - Team With Slider | 9/5/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Sk. Abul Hasan Team Member – Team with Slider plugin <= 4.4 versions. | |
| Modificada | Media (5.4) | 0.50% | — | Shapedplugin Product Slider FOR Woocommerce | 8/5/2023 | 17/6/2026 | The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Easy Testimonial Slider AND Form | 8/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form plugin <= 1.0.15 versions. | |
| Analizada | Media (4.8) | 0.37% | — | Vibethemes Vslider | 3/5/2023 | 17/6/2026 | Auth. Stored Cross-Site Scripting (XSS) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 versions. | |
| Modificada | Media (5.4) | 0.37% | — | Portfolio Slideshow Project Portfolio Slideshow | 23/4/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in George Gecewicz Portfolio Slideshow plugin <= 1.13.0 versions. | |
| Modificada | Media (6.1) | 0.60% | — | I13websolution Thumbnail Carousel Slider | 18/4/2023 | 17/6/2026 | The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Media (6.1) | 0.46% | — | Metaslider Slider, Gallery, AND Carousel | 17/4/2023 | 17/6/2026 | The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.48% | — | Nextendweb Smart Slider 3 | 27/3/2023 | 17/6/2026 | The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.3) | 0.26% | — | Hasthemes HT Slider FOR Elementor | 27/3/2023 | 17/6/2026 | The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack |