Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
2445 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.23% | — | Pluginscafe Range Slider Addon FOR Gravity FormsAI | 6/11/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsCafe Range Slider Addon for Gravity Forms range-slider-addon-for-gravity-forms allows Reflected XSS.This issue affects Range Slider Addon for Gravity Forms: from n/a through <= 1.1.6. | |
| Aplazada | Alta (8.8) | 0.35% | — | Bplugins Advanced ScrollbarAI | 6/11/2025 | 7/10/2026 | Incorrect Privilege Assignment vulnerability in bPlugins Advanced scrollbar advanced-scrollbar allows Privilege Escalation.This issue affects Advanced scrollbar: from n/a through <= 1.1.8. | |
| Aplazada | Alta (7.1) | 0.29% | — | Bplugins Image Gallery BlockAI | 6/11/2025 | 7/10/2026 | Missing Authorization vulnerability in bPlugins Image Gallery block – Create and display photo gallery/photo album. 3d-image-gallery allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Image Gallery block – Create and display photo gallery/photo album.: from n/a through <= 1.0.7. | |
| Aplazada | Alta (8.6) | 0.33% | — | Bplugins Document EmbedderAI | 5/11/2025 | 17/6/2026 | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action in the… | |
| Aplazada | Alta (7.5) | 7.0% | — | Glpi Inventory PluginAI | 4/11/2025 | 17/6/2026 | The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Versions 1.5.0 and below are vulnerable to SQL Injection. This issue is fixed in version 1.5.1. | |
| Aplazada | Media (6.1) | 0.16% | — | Associados Amazon PluginAI | 4/11/2025 | 17/6/2026 | The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to missing or incorrect nonce validation on the brzon_admin_panel() function. This makes it possible for unauthenticated attackers to update settings and inject malicious… | |
| Aplazada | Alta (8.8) | 0.66% | — | Jewel Theme Recommended Plugins LibraryAI | 4/11/2025 | 17/6/2026 | Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of File with Dangerous Type via arbitrary plugin installation in all versions up to, and including, 1.0.2.3. This is due to missing capability checks on the '*_recommended_upgrade_plugin' function… | |
| Aplazada | Media (6.1) | 0.16% | — | Label PluginsAI | 4/11/2025 | 17/6/2026 | The Label Plugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect nonce validation on the label_plugins_options() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Aplazada | Media (4.3) | 0.13% | — | Sigmaplugin Advanced Database CleanerAI | 31/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allows Cross Site Request Forgery.This issue affects Advanced Database Cleaner: from n/a through <= 3.1.6. | |
| Aplazada | Media (4.3) | 0.22% | — | Fantasticplugins Sumo Affiliates PROAI | 29/10/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Retrieve Embedded Sensitive Data.This issue affects SUMO Affiliates Pro: from n/a through <= 11.0.0. | |
| Modificada | Media (6.5) | 0.17% | — | Xlplugins Nextmove | 27/10/2025 | 8/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Stored XSS.This issue affects NextMove Lite: from n/a through <= 2.23.0. | |
| Aplazada | Media (6.5) | 0.33% | — | Pickplugins Testimonial SliderAI | 27/10/2025 | 8/10/2026 | Missing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonial Slider: from n/a through <= 2.0.15. | |
| Aplazada | Media (6.5) | 0.33% | — | Pickplugins Post GridAIPickplugins Gutenberg BlocksAI | 27/10/2025 | 8/10/2026 | Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17. | |
| Aplazada | Media (6.5) | 0.20% | — | Aviplugins Custom Post Type AttachmentAI | 27/10/2025 | 8/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Custom Post Type Attachment custom-post-type-pdf-attachment allows Stored XSS.This issue affects Custom Post Type Attachment: from n/a through <= 3.4.6. | |
| Aplazada | Media (4.3) | 0.23% | — | Sigmaplugin Advanced Database CleanerAI | 25/10/2025 | 8/10/2026 | The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to missing or incorrect nonce validation on the aDBc_prepare_elements_to_clean() function. This makes it possible for unauthenticated attackers to alter the keep last… | |
| Aplazada | Media (6.3) | 0.27% | — | URL Shortener Plugin FOR WordpressAI | 24/10/2025 | 8/10/2026 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provided by the API due to a missing capability check on the verifyRequest function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.4) | 0.24% | — | Wpplugin Time ClockAI | 24/10/2025 | 8/10/2026 | The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 1.3.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Alta (8.1) | 0.27% | — | Openbao AWS Plugin | 23/10/2025 | 8/10/2026 | OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Impersonation in the AWS auth method. The vulnerability allows an IAM role from an untrusted AWS account to authenticate by impersonating a role with the same name… | |
| Modificada | Alta (7.1) | 0.30% | — | Xlplugins Nextmove | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Reflected XSS.This issue affects NextMove Lite: from n/a through <= 2.24.0. | |
| Aplazada | Alta (8.8) | 0.38% | — | Bplugins Voice FeedbackAI | 22/10/2025 | 8/10/2026 | Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback: from n/a through <= 1.0.3. | |
| Aplazada | Alta (7.1) | 0.14% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 8/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Cross Site Request Forgery.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0. | |
| Aplazada | Alta (8.8) | 0.39% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 8/10/2026 | Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Privilege Escalation.This issue affects SUMO Memberships for WooCommerce: from n/a through <= 7.8.0. | |
| Aplazada | Media (6.5) | 0.32% | — | Pickplugins AccordionAI | 22/10/2025 | 8/10/2026 | Missing Authorization vulnerability in PickPlugins Accordion accordions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion: from n/a through <= 2.3.14. | |
| Aplazada | Alta (7.1) | 0.25% | — | Toast Plugins Toast Mobile MenuAI | 22/10/2025 | 8/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toast Plugins Toast Mobile Menu toast-responsive-menu allows Stored XSS.This issue affects Toast Mobile Menu: from n/a through <= 1.0.8. | |
| Aplazada | Media (6.5) | 0.27% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 8/10/2026 | Missing Authorization vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0. |