Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
2445 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.30% | — | Prowcplugins Product Countdown FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProWCPlugins Product Time Countdown for WooCommerce product-countdown-for-woocommerce allows Stored XSS.This issue affects Product Time Countdown for WooCommerce: from n/a through <= 1.6.5. | |
| Aplazada | Media (6.5) | 0.27% | — | HT Plugins HT Mega - Absolute Addons FOR Wpbakery Page BuilderAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega – Absolute Addons for WPBakery Page Builder ht-mega-for-wpbakery allows DOM-Based XSS.This issue affects HT Mega – Absolute Addons for WPBakery Page Builder: from n/a through <= 1.0.9. | |
| Aplazada | Alta (7.5) | 0.67% | — | Pluginwale Easy Pricing Table WPAI | 22/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Pluginwale Easy Pricing Table WP easy-pricing-table-wp allows PHP Local File Inclusion.This issue affects Easy Pricing Table WP: from n/a through <= 1.1.3. | |
| Aplazada | Baja (2.9) | 0.38% | — | Cloudflare Vite PluginAI | 19/9/2025 | 17/6/2026 | The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as .env and .dev.vars.… | |
| Aplazada | Media (5.4) | 0.13% | — | Hack Repair GUY Plugin ArchiverAI | 17/9/2025 | 25/9/2026 | El plugin Plugin Archiver de The Hack Repair Guy para WordPress es vulnerable a Cross-Site Request Forgery en todas las versiones hasta la 2.0.4, inclusive. Esto se debe a la validación de nonce faltante o incorrecta en la función bulk_remove(). Esto hace posible que atacantes no autenticados realicen la eliminación… | |
| Aplazada | Alta (7.2) | 0.73% | — | Hack Repair GUY Plugin ArchiverAI | 12/9/2025 | 17/6/2026 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the prepare_items function in all versions up to, and including, 2.0.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Media (6.4) | 0.20% | — | Enhanced BibliplugAI | 11/9/2025 | 17/6/2026 | The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_authors' shortcode in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.13% | — | Plugin Updates BlockerAI | 11/9/2025 | 17/6/2026 | The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the pub_save action handler. This makes it possible for unauthenticated attackers to disable or enable plugin updates via a… | |
| Aplazada | Alta (8.8) | 0.33% | — | Resideo PluginAI | 10/9/2025 | 25/9/2026 | El plugin Resideo Plugin for Resideo - Real Estate WordPress Theme para WordPress es vulnerable a escalada de privilegios mediante toma de control de cuenta en todas las versiones hasta la 2.5.4, inclusive. Esto se debe a que el plugin no valida correctamente la identidad de un usuario antes de actualizar sus detalles… | |
| Aplazada | Media (6.6) | 0.11% | — | Zoom Workplace VDI PluginAIVmware HorizonAI | 9/9/2025 | 17/6/2026 | Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective tracks) may allow an authenticated user to conduct a disclosure of information via network access. | |
| Aplazada | Media (6.5) | 0.17% | — | Silverplugins217 Dynamic Text Field FOR Contact Form 7AI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 Dynamic Text Field For Contact Form 7 dynamic-text-field-for-contact-form-7 allows Stored XSS.This issue affects Dynamic Text Field For Contact Form 7: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.40% | — | Pluginus Inpost GalleryAI | 5/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 InPost Gallery inpost-gallery allows PHP Local File Inclusion.This issue affects InPost Gallery: from n/a through <= 2.1.4.5. | |
| Aplazada | Media (4.3) | 0.13% | — | Fullworksplugins Quick Paypal PaymentsAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in fullworks Quick Paypal Payments quick-paypal-payments allows Cross Site Request Forgery.This issue affects Quick Paypal Payments: from n/a through <= 5.7.46. | |
| Aplazada | Media (6.5) | 0.17% | — | George Sexton Wordpress Events Calendar Plugin ConnectdailyAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Sexton WordPress Events Calendar Plugin – connectDaily connect-daily-web-calendar allows Stored XSS.This issue affects WordPress Events Calendar Plugin – connectDaily: from n/a through <= 1.5.5. | |
| Aplazada | Baja (3.8) | 0.25% | — | Pickplugins JOB Board ManagerAI | 5/9/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Baja (3.5) | 0.25% | — | Plugin-devs Ecommerce-product-carousel-slider-for-elementorAI | 5/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Plugin Devs Product Carousel Slider for Elementor ecommerce-product-carousel-slider-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Carousel Slider for Elementor: from n/a through <= 2.1.3. | |
| Aplazada | Media (5.1) | 0.10% | — | Obsidian Github Copilot PluginAI | 5/9/2025 | 17/6/2026 | Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account. | |
| Aplazada | Media (5.9) | 0.18% | — | Spiffyplugins WP Flow PlusAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allows Stored XSS.This issue affects WP Flow Plus: from n/a through <= 5.2.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Bohemia Plugins Event Feed FOR EventbriteAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bohemia Plugins Event Feed for Eventbrite event-feed-for-eventbrite allows DOM-Based XSS.This issue affects Event Feed for Eventbrite: from n/a through <= 1.3.2. | |
| Aplazada | Media (5.3) | 0.29% | — | Barn2 Plugins Posts Table With Search AND SortAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Barn2 Plugins Posts Table with Search & Sort posts-data-table allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Posts Table with Search & Sort: from n/a through <= 1.4.10. | |
| Aplazada | Crítica (9.8) | 6.5% | 💥 PoC | Kamleshyadav Miraculous Core PluginAI | 28/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Privilege Escalation.This issue affects Miraculous Core Plugin: from n/a through <= 2.0.7. | |
| Aplazada | Alta (7.1) | 0.13% | — | Pluginspoint Kento Splash ScreenAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PluginsPoint Kento Splash Screen kento-splash-screen allows Stored XSS.This issue affects Kento Splash Screen: from n/a through <= 1.4. | |
| Aplazada | Media (5.8) | 0.22% | — | Bplugins B SliderAI | 28/8/2025 | 25/9/2026 | Vulnerabilidad por falta de autorización en bPlugins B Slider permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a B Slider: desde n/a hasta 1.1.30. | |
| Aplazada | Alta (7.1) | 0.24% | — | Bplugins Tiktok FeedAI | 28/8/2025 | 25/9/2026 | Vulnerabilidad por falta de autorización en bPlugins Tiktok Feed permite acceder a funcionalidades no debidamente restringidas por ACLs. Este problema afecta a Tiktok Feed: desde n/a hasta 1.0.21. | |
| Aplazada | Media (4.3) | 0.13% | — | Pluginsandsnippets Simple Page Access RestrictionAI | 27/8/2025 | 17/6/2026 | Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Plugins and Snippets Simple Page Access Restriction permite Cross-Site Request Forgery. Este problema afecta a Simple Page Access Restriction: desde n/d hasta la versión 1.0.32. |