Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.50% | — | Deco.agency DE BrandingAI | 20/11/2024 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:branding: from n/a through <= 1.0.2. | |
| Aplazada | Media (6.5) | 0.36% | — | Jakeatthrive Brand MY FooterAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jakeatthrive Brand my Footer brand-my-footer allows DOM-Based XSS.This issue affects Brand my Footer: from n/a through <= 1.1. | |
| Modificada | Media (5.4) | 0.26% | — | Brandevolutionco Themeshark Templates & Widgets FOR Elementor | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeshark ThemeShark Templates & Widgets for Elementor themeshark-elementor allows Stored XSS.This issue affects ThemeShark Templates & Widgets for Elementor: from n/a through <= 1.1.7. | |
| Modificada | Alta (8.8) | 0.44% | — | Brandonwhite Author Discussion | 20/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion author-discussion allows Blind SQL Injection.This issue affects Author Discussion: from n/a through <= 0.2.2. | |
| Modificada | Crítica (9.8) | 0.52% | — | Brandonclark Sitebuilder Dynamic Components | 20/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components allows Object Injection.This issue affects SiteBuilder Dynamic Components: from n/a through <= 1.0. | |
| Analizada | Media (5.4) | 0.31% | — | Tahoe Debrandify | 18/10/2024 | 17/6/2026 | The Debrandify · Remove or Replace WordPress Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | |
| Analizada | Media (5.4) | 0.30% | — | Gurieveugen&vitaliyshebela Branding | 18/10/2024 | 17/6/2026 | The Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web… | |
| Analizada | Media (5.4) | 0.30% | — | Wp-brandtheme Preloader Plus | 7/9/2024 | 17/6/2026 | The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | |
| Modificada | Media (4.8) | 0.26% | — | Wpmudev Branda | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Branda branda-white-labeling.This issue affects Branda: from n/a through <= 3.4.17. | |
| Aplazada | Media (5.5) | 0.36% | — | WP Total BrandingAI | 12/7/2024 | 17/6/2026 | The WP Total Branding – Complete branding solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.3) | 0.45% | — | Wpmudev Branda | 11/7/2024 | 17/6/2026 | The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.18. This is due the plugin utilizing composer without preventing direct access to the files. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.4) | 0.31% | — | Wpmudev Branda | 21/6/2024 | 17/6/2026 | The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_types’ parameter in all versions up to, and including, 3.4.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.37% | — | Wpmudev BrandaAI | 4/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in WPMU DEV Branda allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Branda: from n/a through 3.4.14. | |
| Modificada | Media (5.3) | 0.52% | — | Brandonwamboldt Wordpress Access Control | 28/2/2024 | 17/6/2026 | The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Make Website Members Only" feature (when unset) and view restricted page and post… | |
| Modificada | Crítica (9.8) | 0.52% | — | Mypresta Manufacturers (brands) Images Block | 19/1/2024 | 17/6/2026 | In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The methods `mib::getManufacturersByCategory()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Alta (8.8) | 0.31% | — | Brandbrilliance Post State Tags | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BRANDbrilliance Post State Tags plugin <= 2.0.6 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Featherplugins Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions. | |
| Modificada | Crítica (9.8) | 0.64% | — | Themevolty Theme Volty CMS Brandlist | 3/10/2023 | 17/6/2026 | Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty CMS BrandList” (tvcmsbrandlist) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions. | |
| Modificada | Media (5.4) | 0.38% | — | Woocommerce Brands | 30/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.45 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Brandid Social Proof (testimonial) Slider | 10/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in brandiD Social Proof (Testimonial) Slider plugin <= 2.2.3 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Woocommerce Brands | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.49 versions. | |
| Modificada | Media (6.1) | 0.66% | — | Woocommerce Wooframework Branding | 5/6/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of the argument url leads to open redirect. It is possible to launch the attack remotely. Upgrading to… | |
| Modificada | Media (5.4) | 0.36% | — | Berocket Brands FOR Woocommerce | 18/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0.6 versions. | |
| Modificada | Media (4.8) | 0.39% | — | White Label Branding FOR Elementor Page Builder Project White Label Branding FOR Elementor Page Builder | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page Builder plugin <= 1.0.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | WSB Brands Project WSB Brands | 8/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Branko Borilovic WSB Brands plugin <= 1.1.8 versions. |