Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1062 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)98%💥 ExploitWordpressFedoraproject FedoraDebian Linux6/1/202217/6/2026
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older…
ModificadaMedia (4.8)0.62%—Reputeinfosystems Contact Form, Survey & Popup Form Plugin FOR Wordpress - Arforms Form Builder6/12/202117/6/2026
The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaCrítica (9.8)29%—Wordpress25/11/202117/6/2026
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet…
ModificadaAlta (8.8)0.67%—Delitestudio Push Notifications FOR Wordpress24/11/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.
ModificadaMedia (6.1)0.97%—Wpo365 Wordpress + Azure AD / Microsoft Office 36519/11/202117/6/2026
The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper…
ModificadaAlta (8.8)80%💥 ExploitWordpress Popular Posts Project Wordpress Popular Posts17/11/202117/6/2026
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution,…
ModificadaMedia (5.4)0.58%—Wordpress Popular Posts Project Wordpress Popular Posts23/9/202117/6/2026
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].
ModificadaMedia (4.8)0.62%—Ticket-system Wordpress Advanced Ticket System13/9/202117/6/2026
The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape form values before saving to the database or when outputting, which allows high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.1)0.90%—Wordpress Simple Shop Project Wordpress Simple Shop10/9/202117/6/2026
The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.
ModificadaMedia (6.5)0.94%—Wordpress9/9/202117/6/2026
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in the block editor under certain conditions. This affected WordPress 5.8…
ModificadaMedia (5.4)0.82%—Wordpress9/9/202117/6/2026
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom HTML widget. This…
ModificadaMedia (5.4)1.5%—WordpressDebian Linux9/9/202117/6/2026
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions imposed on users who do not have the…
ModificadaMedia (5.3)2.0%—WordpressDebian Linux9/9/202117/6/2026
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to perform actions on your behalf. This has…
ModificadaMedia (4.3)0.45%—Shantz Wordpress Qotd Project Shantz Wordpress Qotd16/8/202117/6/2026
The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing attackers to make logged in administrators change them to arbitrary values.
ModificadaAlta (7.5)1.4%—Gatsbyjs Gatsby-source-wordpress15/7/202117/6/2026
Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authentication variables into the app.js bundle during build-time. Users who are not initializing basic authentication credentials in the gatsby-config.js are not affected. A…
ModificadaAlta (8.8)0.85%—Pluginus Wordpress Meta Data AND Taxonomies Filter14/7/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in WordPress Meta Data Filter & Taxonomies Filter versions prior to v.1.2.8 and versions prior to v.2.2.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaAlta (8.8)0.87%—Wp-currency Wordpress Currency Switcher7/7/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaAlta (8.8)0.87%—Codemiq Wordpress Email Template Designer7/7/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaMedia (5.4)1.4%—Wordpress Popular Posts Project Wordpress Popular Posts28/6/202117/6/2026
Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
ModificadaCrítica (9.8)3.1%—Phpmailer Project PhpmailerWordpress28/4/202117/6/2026
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an…
ModificadaCrítica (9.8)2.1%—Wordpress Requests27/4/202117/6/2026
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.
ModificadaMedia (4.3)2.1%—WordpressDebian Linux15/4/202117/6/2026
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It's strongly…
ModificadaMedia (6.5)86%💥 ExploitWordpressDebian Linux15/4/202117/6/2026
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in…
ModificadaMedia (6.5)0.57%—Patreon Wordpress12/4/202117/6/2026
The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged administrator disconnect the site from Patreon by visiting a specially crafted link.
ModificadaAlta (8.1)0.60%—Patreon Wordpress12/4/202117/6/2026
The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or create arbitrary user metadata on the victim’s account once visited. If exploited, this bug can be used to overwrite the “wp_capabilities”…
Orbitaley — Vulnerabilidades