Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2772▲ 13 respecto a la semana anterior
Críticas / altas1288▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

3380 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.13%—Presspage Entertainment INC Mavis Https TO Http RedirectionAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PressPage Entertainment Inc Mavis HTTPS to HTTP Redirection mavis-https-to-http-redirect allows Stored XSS.This issue affects Mavis HTTPS to HTTP Redirection: from n/a through <= 1.4.3.
AplazadaMedia (6.5)0.21%—Dtbaker Stylepress FOR ElementorAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dtbaker StylePress for Elementor full-site-builder-for-elementor allows Stored XSS.This issue affects StylePress for Elementor: from n/a through <= 1.2.1.
AplazadaMedia (4.3)0.27%—Motopress GetwidAI22/9/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in jetmonsters Getwid getwid allows Retrieve Embedded Sensitive Data.This issue affects Getwid: from n/a through <= 2.1.2.
AplazadaMedia (6.5)0.28%—Ontraport PilotpressAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ONTRAPORT PilotPress pilotpress allows Stored XSS.This issue affects PilotPress: from n/a through <= 2.0.36.
AplazadaMedia (4.3)0.25%—Ontraport PilotpressAI22/9/202517/6/2026
Missing Authorization vulnerability in ONTRAPORT PilotPress pilotpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PilotPress: from n/a through <= 2.0.36.
AplazadaMedia (6.5)0.31%—Slimndap Theater FOR WordpressAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Theater for WordPress theatre allows Stored XSS.This issue affects Theater for WordPress: from n/a through <= 0.18.8.
AplazadaMedia (4.3)0.29%—Nerdpress Hubbub LiteAI22/9/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NerdPress Hubbub Lite social-pug allows Retrieve Embedded Sensitive Data.This issue affects Hubbub Lite: from n/a through <= 1.35.2.
AplazadaMedia (6.5)0.20%—Milan Petrovic GD GD Bbpress ToolsAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD bbPress Tools gd-bbpress-tools allows DOM-Based XSS.This issue affects GD bbPress Tools: from n/a through <= 3.5.3.
AplazadaMedia (6.5)0.22%—Brajesh Singh Wordpress Widgets ShortcodeAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brajesh Singh WordPress Widgets Shortcode wp-widgets-shortcode allows Stored XSS.This issue affects WordPress Widgets Shortcode: from n/a through <= 1.0.3.
AplazadaMedia (5.3)0.28%—Thimpress WP Events ManagerAI22/9/202517/6/2026
Missing Authorization vulnerability in ThimPress WP Events Manager wp-events-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Events Manager: from n/a through <= 2.2.1.
AplazadaMedia (5.3)0.32%—Strategy11 Another Wordpress Classifieds PluginAI22/9/202517/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Code Injection.This issue affects AWP Classifieds: from n/a through <= 4.4.3.
AplazadaMedia (5.9)0.22%—Tmontg1 Form Generator FOR WordpressAIJotformAI22/9/202530/9/2026
Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en tmontg1 Form Generator para WordPress permite XSS Almacenado. Este problema afecta a Form Generator para WordPress: desde n/a hasta 1.5.2.
AplazadaMedia (5.9)0.22%—VoucherpressAI22/9/202530/9/2026
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Chris Taylor VoucherPress permite XSS Almacenado. Este problema afecta a VoucherPress: desde n/d hasta 1.5.7.
AplazadaMedia (5.3)0.46%—Wpcompress WP CompressAI22/9/202530/9/2026
Vulnerabilidad de autorización faltante en AresIT WP Compress permite acceder a funcionalidades no restringidas adecuadamente por ACLs. Este problema afecta a WP Compress: desde n/a hasta 6.50.54.
AnalizadaAlta (8.8)0.61%—Yandaozi Ppress19/9/202517/6/2026
Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.
AnalizadaAlta (8)0.33%—Yandaozi Ppress19/9/202517/6/2026
An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.
AnalizadaAlta (8.8)0.42%—Yandaozi Ppress19/9/202517/6/2026
Hardcoded credentials in default configuration of PPress 0.0.9.
AplazadaBaja (2.7)0.44%—Frappe PressAI18/9/202517/6/2026
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). A bad actor can flood the inbox of a user by repeatedly sending invites (duplicate). The issue is fixed in commit 83c3fc7676c5dbbe1fd5092d21d95a10c7b48615.
AplazadaCrítica (9.1)0.30%—Thimpress WP Hotel BookingAI18/9/202517/6/2026
The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests.
AplazadaCrítica (9.8)0.24%—Bedevious Password Reset With Code FOR Wordpress Rest APIAI18/9/202517/6/2026
The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.
AplazadaMedia (5.3)0.45%—Express-xss-sanitizerAI14/9/202517/6/2026
The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth in sanitize in lib/sanitize.js for a JSON request body.
AplazadaAlta (7.2)0.56%—Import ANY XML CSV OR Excel File TO WordpressAI10/9/202517/6/2026
The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functionality in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to…
AnalizadaCrítica (9.3)0.66%—Opexustech Foiaxpress Public Access Link9/9/202530/9/2026
OPEXUS FOIAXpress Public Access Link (PAL) anterior a la versión 11.13.1.0 permite la inyección SQL a través de SearchPopularDocs.aspx. Un atacante remoto no autenticado podría leer, escribir o eliminar cualquier contenido en la base de datos subyacente.
AplazadaAlta (7.6)0.28%—Presstigers ZIP Code Based Content ProtectionAI9/9/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection zip-code-based-content-protection allows SQL Injection.This issue affects ZIP Code Based Content Protection: from n/a through <= 1.0.0.
AplazadaAlta (8.8)0.33%—Webdevstudios Constant Contact FOR WordpressAI9/9/202517/6/2026
Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: from n/a through 4.1.1.