Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 0.28% | — | Termly Gdpr Cookie Consent Banner | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2. | |
| Modificada | Media (5.4) | 0.28% | — | Ninjateam Gdpr Ccpa Compliance & Cookie Consent Banner | 7/6/2024 | 17/6/2026 | The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions named ajaxUpdateSettings() in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.9) | 0.28% | — | Buffercode Random BannerAI | 2/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Random Banner random-banner allows DOM-Based XSS.This issue affects Random Banner: from n/a through <= 4.2.12. | |
| Aplazada | Media (5.9) | 0.44% | — | Hidden Depth Sticky BannerAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Sticky banner allows Stored XSS.This issue affects Sticky banner: from n/a through 1.2.0. | |
| Aplazada | Media (5.9) | 0.44% | — | Orchestrated Corona Virus Covid-19 Banner AND Live DataAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Orchestrated Corona Virus (COVID-19) Banner & Live Data allows Stored XSS.This issue affects Corona Virus (COVID-19) Banner & Live Data: from n/a through 1.8.0.2. | |
| Analizada | Media (5.5) | 0.43% | — | WEB LID Bannerlid | 26/4/2024 | 17/6/2026 | The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators | |
| Modificada | Media (6.5) | 0.59% | 💥 PoC | Ellucian Banner | 13/2/2024 | 17/6/2026 | Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint. | |
| Modificada | Media (4.8) | 0.38% | — | Bannersky BSK Forms Blacklist | 26/12/2023 | 17/6/2026 | The BSK Forms Blacklist WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.5) | 0.63% | — | Bannersky BSK Forms Blacklist | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BannerSky BSK Forms Blacklist.This issue affects BSK Forms Blacklist: from n/a through 3.6.2. | |
| Modificada | Media (6.1) | 0.44% | — | Bannersky BSK Contact Form 7 Blacklist | 4/12/2023 | 17/6/2026 | The BSK Contact Form 7 Blacklist WordPress plugin through 1.0.1 does not sanitise and escape the inserted_count parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (8.8) | 0.31% | — | Robinphillips Mobile Banner | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Robin Phillips Mobile Banner plugin <= 1.5 versions. | |
| Modificada | Media (5.4) | 0.52% | — | Spicethemes Carousel, Recent Post Slider AND Banner Slider | 30/10/2023 | 17/6/2026 | The Carousel, Recent Post Slider and Banner Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'spice_post_slider' shortcode in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (4.8) | 0.31% | — | Wandlesoftware Smart APP Banner | 27/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Stephen Darlington, Wandle Software Limited Smart App Banner plugin <= 1.1.3 versions. | |
| Modificada | Media (5.4) | 0.45% | — | Bannersky BSK PDF Manager | 25/10/2023 | 17/6/2026 | The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bsk-pdfm-category-dropdown' shortcode in versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (6.5) | 0.22% | — | Multidots Banner Management FOR Woocommerce | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Banner Management For WooCommerce plugin <= 2.4.2 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Undolog WP Bannerize PRO | 29/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Giovambattista Fazioli WP Bannerize Pro plugin <= 1.6.9 versions. | |
| Modificada | Media (4.3) | 0.38% | — | Goldplugins Custom Banners | 12/7/2023 | 17/6/2026 | The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted… | |
| Modificada | Media (6.1) | 84% | 💥 Exploit | Beautiful-cookie-banner Beautiful Cookie Consent Banner | 24/6/2023 | 17/6/2026 | The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (5.4) | 0.29% | — | Announcement & Notification Banner - Bulletin | 9/6/2023 | 17/6/2026 | The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce validation on the 'bulletinwp_update_bulletin_status', 'bulletinwp_update_bulletin', 'bulletinwp_update_settings', 'bulletinwp_update_status', 'bulletinwp_export_bulletins', and… | |
| Modificada | Media (4.3) | 0.51% | — | Announcement & Notification Banner - Bulletin | 9/6/2023 | 17/6/2026 | The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'bulletinwp_update_bulletin_status', 'bulletinwp_update_bulletin', 'bulletinwp_update_settings', 'bulletinwp_update_status',… | |
| Modificada | Alta (8.8) | 0.26% | — | Wandlesoftware Smart APP Banner | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stephen Darlington, Wandle Software Limited Smart App Banner plugin <= 1.1.2 versions. | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Full Width Banner Slider WP | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Full Width Banner Slider Wp plugin <= 1.1.7 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Essentialplugin Hero Banner Ultimate | 4/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate plugin <= 1.3.4 versions. | |
| Modificada | Alta (8.8) | 0.87% | — | Accesspressthemes WP Popup Banners | 22/3/2023 | 17/6/2026 | The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action. | |
| Modificada | Media (6.5) | 0.94% | — | WP Popup Banners Project WP Popup Banners | 17/3/2023 | 17/6/2026 | The WP Popup Banners plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' parameter in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers… |