Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
–

723 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.26%—Web-settler Layer Slider11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions.
ModificadaMedia (4.8)0.42%—Qumos Mojoplug Slide Panel22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Qumos MojoPlug Slide Panel plugin <= 1.1.2 versions.
ModificadaAlta (8.8)2.5%—Themepunch Slider Revolution19/6/202317/6/2026
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
ModificadaMedia (5.4)0.44%—Slideonline Project Sideonline19/6/202317/6/2026
The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)0.43%—I13websolution Team Circle Image Slider With Lightbox9/6/202317/6/2026
The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
ModificadaMedia (6.1)0.43%—I13websolution Photo Gallery Slideshow & Masonry Tiled Gallery9/6/202317/6/2026
The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
ModificadaMedia (6.1)0.43%—I13websolution Wordpress Vertical Image Slider9/6/202317/6/2026
The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
ModificadaMedia (4.3)0.71%—2joomla 2J Slideshow7/6/202317/6/2026
The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'twoj_slideshow_setup' function called via the wp_ajax_twoj_slideshow_setup AJAX action in versions up to, and including, 1.3.31. This makes it possible for authenticated attackers (Subscriber, or above…
ModificadaCrítica (9.8)0.67%—Joommasters JMS Slider5/6/202317/6/2026
PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.
ModificadaAlta (8.8)0.26%—Codeixer Product Gallery Slider FOR Woocommerce29/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Codeixer Product Gallery Slider for WooCommerce plugin <= 2.2.8 versions.
ModificadaAlta (8.8)0.27%—WP Tabs Slides Project WP Tabs Slides22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Abdul Ibad WP Tabs Slides plugin <= 2.0.3 versions.
ModificadaAlta (8.8)0.26%—Ljapps WP Airbnb Review Slider20/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in LJ Apps WP Airbnb Review Slider plugin <= 3.2 versions.
ModificadaMedia (6.1)0.61%—I13websolution Video Carousel Slider With Lightbox16/5/202317/6/2026
The video carousel slider with lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
ModificadaMedia (6.1)0.48%—I13websolution Thumbnail Carousel Slider15/5/202317/6/2026
The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting vulnerability which could be used against high privilege users such as admin.
ModificadaMedia (4.8)0.37%—Gopiplus Tiny Carousel Horizontal Slider Plus10/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Tiny carousel horizontal slider plus plugin <= 3.2 versions.
ModificadaMedia (6.1)0.38%—I13websolution Full Width Banner Slider WP10/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Full Width Banner Slider Wp plugin <= 1.1.7 versions.
ModificadaMedia (5.4)0.37%—Wpmart Team Member - Team With Slider9/5/202317/6/2026
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Sk. Abul Hasan Team Member – Team with Slider plugin <= 4.4 versions.
ModificadaMedia (5.4)0.50%—Shapedplugin Product Slider FOR Woocommerce8/5/202317/6/2026
The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)0.38%—I13websolution Easy Testimonial Slider AND Form8/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form plugin <= 1.0.15 versions.
AnalizadaMedia (4.8)0.37%—Vibethemes Vslider3/5/202317/6/2026
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 versions.
ModificadaMedia (5.4)0.37%—Portfolio Slideshow Project Portfolio Slideshow23/4/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in George Gecewicz Portfolio Slideshow plugin <= 1.13.0 versions.
ModificadaMedia (6.1)0.60%—I13websolution Thumbnail Carousel Slider18/4/202317/6/2026
The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
ModificadaMedia (6.1)0.46%—Metaslider Slider, Gallery, AND Carousel17/4/202317/6/2026
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (5.4)0.48%—Nextendweb Smart Slider 327/3/202317/6/2026
The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (4.3)0.26%—Hasthemes HT Slider FOR Elementor27/3/202317/6/2026
The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack