Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2772▲ 13 respecto a la semana anterior
Críticas / altas1288▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
3380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.13% | — | Presspage Entertainment INC Mavis Https TO Http RedirectionAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressPage Entertainment Inc Mavis HTTPS to HTTP Redirection mavis-https-to-http-redirect allows Stored XSS.This issue affects Mavis HTTPS to HTTP Redirection: from n/a through <= 1.4.3. | |
| Aplazada | Media (6.5) | 0.21% | — | Dtbaker Stylepress FOR ElementorAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dtbaker StylePress for Elementor full-site-builder-for-elementor allows Stored XSS.This issue affects StylePress for Elementor: from n/a through <= 1.2.1. | |
| Aplazada | Media (4.3) | 0.27% | — | Motopress GetwidAI | 22/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in jetmonsters Getwid getwid allows Retrieve Embedded Sensitive Data.This issue affects Getwid: from n/a through <= 2.1.2. | |
| Aplazada | Media (6.5) | 0.28% | — | Ontraport PilotpressAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ONTRAPORT PilotPress pilotpress allows Stored XSS.This issue affects PilotPress: from n/a through <= 2.0.36. | |
| Aplazada | Media (4.3) | 0.25% | — | Ontraport PilotpressAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in ONTRAPORT PilotPress pilotpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PilotPress: from n/a through <= 2.0.36. | |
| Aplazada | Media (6.5) | 0.31% | — | Slimndap Theater FOR WordpressAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Theater for WordPress theatre allows Stored XSS.This issue affects Theater for WordPress: from n/a through <= 0.18.8. | |
| Aplazada | Media (4.3) | 0.29% | — | Nerdpress Hubbub LiteAI | 22/9/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NerdPress Hubbub Lite social-pug allows Retrieve Embedded Sensitive Data.This issue affects Hubbub Lite: from n/a through <= 1.35.2. | |
| Aplazada | Media (6.5) | 0.20% | — | Milan Petrovic GD GD Bbpress ToolsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD bbPress Tools gd-bbpress-tools allows DOM-Based XSS.This issue affects GD bbPress Tools: from n/a through <= 3.5.3. | |
| Aplazada | Media (6.5) | 0.22% | — | Brajesh Singh Wordpress Widgets ShortcodeAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brajesh Singh WordPress Widgets Shortcode wp-widgets-shortcode allows Stored XSS.This issue affects WordPress Widgets Shortcode: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.3) | 0.28% | — | Thimpress WP Events ManagerAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in ThimPress WP Events Manager wp-events-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Events Manager: from n/a through <= 2.2.1. | |
| Aplazada | Media (5.3) | 0.32% | — | Strategy11 Another Wordpress Classifieds PluginAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Code Injection.This issue affects AWP Classifieds: from n/a through <= 4.4.3. | |
| Aplazada | Media (5.9) | 0.22% | — | Tmontg1 Form Generator FOR WordpressAIJotformAI | 22/9/2025 | 30/9/2026 | Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en tmontg1 Form Generator para WordPress permite XSS Almacenado. Este problema afecta a Form Generator para WordPress: desde n/a hasta 1.5.2. | |
| Aplazada | Media (5.9) | 0.22% | — | VoucherpressAI | 22/9/2025 | 30/9/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Chris Taylor VoucherPress permite XSS Almacenado. Este problema afecta a VoucherPress: desde n/d hasta 1.5.7. | |
| Aplazada | Media (5.3) | 0.46% | — | Wpcompress WP CompressAI | 22/9/2025 | 30/9/2026 | Vulnerabilidad de autorización faltante en AresIT WP Compress permite acceder a funcionalidades no restringidas adecuadamente por ACLs. Este problema afecta a WP Compress: desde n/a hasta 6.50.54. | |
| Analizada | Alta (8.8) | 0.61% | — | Yandaozi Ppress | 19/9/2025 | 17/6/2026 | Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes. | |
| Analizada | Alta (8) | 0.33% | — | Yandaozi Ppress | 19/9/2025 | 17/6/2026 | An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie. | |
| Analizada | Alta (8.8) | 0.42% | — | Yandaozi Ppress | 19/9/2025 | 17/6/2026 | Hardcoded credentials in default configuration of PPress 0.0.9. | |
| Aplazada | Baja (2.7) | 0.44% | — | Frappe PressAI | 18/9/2025 | 17/6/2026 | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). A bad actor can flood the inbox of a user by repeatedly sending invites (duplicate). The issue is fixed in commit 83c3fc7676c5dbbe1fd5092d21d95a10c7b48615. | |
| Aplazada | Crítica (9.1) | 0.30% | — | Thimpress WP Hotel BookingAI | 18/9/2025 | 17/6/2026 | The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests. | |
| Aplazada | Crítica (9.8) | 0.24% | — | Bedevious Password Reset With Code FOR Wordpress Rest APIAI | 18/9/2025 | 17/6/2026 | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers. | |
| Aplazada | Media (5.3) | 0.45% | — | Express-xss-sanitizerAI | 14/9/2025 | 17/6/2026 | The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth in sanitize in lib/sanitize.js for a JSON request body. | |
| Aplazada | Alta (7.2) | 0.56% | — | Import ANY XML CSV OR Excel File TO WordpressAI | 10/9/2025 | 17/6/2026 | The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functionality in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Analizada | Crítica (9.3) | 0.66% | — | Opexustech Foiaxpress Public Access Link | 9/9/2025 | 30/9/2026 | OPEXUS FOIAXpress Public Access Link (PAL) anterior a la versión 11.13.1.0 permite la inyección SQL a través de SearchPopularDocs.aspx. Un atacante remoto no autenticado podría leer, escribir o eliminar cualquier contenido en la base de datos subyacente. | |
| Aplazada | Alta (7.6) | 0.28% | — | Presstigers ZIP Code Based Content ProtectionAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection zip-code-based-content-protection allows SQL Injection.This issue affects ZIP Code Based Content Protection: from n/a through <= 1.0.0. | |
| Aplazada | Alta (8.8) | 0.33% | — | Webdevstudios Constant Contact FOR WordpressAI | 9/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: from n/a through 4.1.1. |