Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
2445 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | E-plugins Directory PROAI | 22/10/2025 | 8/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en e-plugins Directory Pro directory-pro permite XSS Reflejado. Este problema afecta a Directory Pro: desde n/a hasta menor o igual que 2.5.5. | |
| Aplazada | Alta (7.1) | 0.28% | — | Extendons Woocommerce Registration Fields PluginAI | 22/10/2025 | 8/10/2026 | Vulnerabilidad de Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') en el plugin extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields permite XSS Reflejado. Este problema afecta a WooCommerce Registration Fields Plugin -… | |
| Aplazada | Media (6.5) | 0.28% | — | WP Google MAP PluginAI | 15/10/2025 | 8/10/2026 | El plugin WP Google Map Plugin para WordPress es vulnerable a inyección SQL ciega a través del parámetro 'id' del shortcode 'google_map' en todas las versiones hasta la 1.0, inclusive, debido a un escape insuficiente en el parámetro proporcionado por el usuario y la falta de preparación suficiente en la consulta SQL… | |
| Aplazada | Media (6.4) | 0.19% | — | Easy Plugin StatsAI | 11/10/2025 | 17/6/2026 | The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.5) | 0.26% | — | Oplugins Booking ManagerAI | 10/10/2025 | 17/6/2026 | The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted. | |
| Aplazada | Media (6.4) | 0.19% | — | A Simple Multilanguage PluginAI | 3/10/2025 | 17/6/2026 | The A Simple Multilanguage Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'asmp-switcher' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.3) | 0.26% | — | Schema Plugin FOR DiviAI | 3/10/2025 | 17/6/2026 | The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all versions up to, and including, 4.3.2 via deserialization of untrusted input via the wpt_schema_breadcrumbs shortcode. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (8.1) | 0.70% | — | BEI FEN Wordpress Backup PluginAI | 30/9/2025 | 17/6/2026 | El plugin Bei Fen – WordPress Backup Plugin para WordPress es vulnerable a la inclusión local de ficheros en todas las versiones hasta la 1.4.2, inclusive, a través del parámetro 'task'. Esto hace posible que atacantes autenticados, con acceso de nivel Suscriptor y superior, incluyan y ejecuten ficheros .php… | |
| Aplazada | Media (6.5) | 0.34% | — | Mkdocs-include-markdown-pluginAI | 29/9/2025 | 17/6/2026 | mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerability where unvalidated input can collide with substitution placeholders. This issue is fixed in version 7.1.8. | |
| Aplazada | Media (4.8) | 0.18% | — | Postieplugin PostieAI | 29/9/2025 | 17/6/2026 | The Postie WordPress plugin before 1.9.71 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (7.1) | 0.12% | — | Yourplugins Conditional Cart Messages FOR WoocommerceAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in yourplugins Conditional Cart Messages for WooCommerce – YourPlugins.com yourplugins-wc-conditional-cart-notices allows Stored XSS.This issue affects Conditional Cart Messages for WooCommerce – YourPlugins.com: from n/a through <= 1.2.10. | |
| Aplazada | Media (6.5) | 0.22% | — | Pickplugins JOB Board ManagerAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows DOM-Based XSS.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Alta (8.8) | 0.48% | — | Pluginops Testimonial SliderAI | 26/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginOps Testimonial Slider testimonial-add allows PHP Local File Inclusion.This issue affects Testimonial Slider: from n/a through <= 3.5.8.6. | |
| Aplazada | Media (6.5) | 0.22% | — | Themeplugs AuthorsyAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeplugs Authorsy authorsy allows Stored XSS.This issue affects Authorsy: from n/a through <= 1.0.5. | |
| Aplazada | Media (6.4) | 0.24% | — | Kraftplugins Mega ElementsAI | 26/9/2025 | 17/6/2026 | The Mega Elements – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown Timer widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.21% | — | Skyword API PluginAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skyword Skyword API Plugin skyword-plugin allows Stored XSS.This issue affects Skyword API Plugin: from n/a through <= 2.5.3. | |
| Aplazada | Media (6.5) | 0.32% | — | Pickplugins AccordionAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Accordion accordions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion: from n/a through <= 2.3.15. | |
| Aplazada | Alta (7.1) | 0.13% | — | Puravida1976 Shrinktheweb Website Preview PluginAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews shrinktheweb-website-preview-plugin allows Stored XSS.This issue affects ShrinkTheWeb (STW) Website Previews: from n/a through <= 2.8.5. | |
| Aplazada | Media (6.5) | 0.22% | — | Shapedplugin LLC Quick View FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Quick View for WooCommerce woo-quickview allows Stored XSS.This issue affects Quick View for WooCommerce: from n/a through <= 2.2.16. | |
| Aplazada | Media (6.5) | 0.45% | — | Plugin-devs Post Carousel Slider FOR ElementorAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Plugin Devs Post Carousel Slider for Elementor post-carousel-slider-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Carousel Slider for Elementor: from n/a through <= 1.7.0. | |
| Aplazada | Media (6.5) | 0.31% | — | 100plugins Open User MAPAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 100plugins Open User Map open-user-map allows DOM-Based XSS.This issue affects Open User Map: from n/a through <= 1.4.14. | |
| Aplazada | Media (5.9) | 0.30% | — | Glen Scott Plugin Security ScannerAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Glen Scott Plugin Security Scanner plugin-security-scanner allows Stored XSS.This issue affects Plugin Security Scanner: from n/a through <= 2.0.2. | |
| Aplazada | Media (6.5) | 0.27% | — | E-plugins Directory PROAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Directory Pro directory-pro allows DOM-Based XSS.This issue affects Directory Pro: from n/a through <= 2.5.5. | |
| Aplazada | Media (6.5) | 0.22% | — | Portfolio-elementorAIPwrplugins PowerfolioAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Diego Pereira PowerFolio portfolio-elementor allows Stored XSS.This issue affects PowerFolio: from n/a through <= 3.2.1. | |
| Aplazada | Media (5.3) | 0.32% | — | Strategy11 Another Wordpress Classifieds PluginAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Code Injection.This issue affects AWP Classifieds: from n/a through <= 4.4.3. |