Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.21% | — | Wp-kama Kama Click CounterAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timur Kamaev Kama Click Counter kama-clic-counter allows Stored XSS.This issue affects Kama Click Counter: from n/a through <= 4.0.4. | |
| Aplazada | Media (4.9) | 0.30% | — | Flowdee ClickwhaleAI | 20/9/2025 | 17/6/2026 | The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection via the export_csv() function in all versions up to, and including, 2.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | |
| Aplazada | Baja (3.2) | 0.15% | — | Clickstudios PasswordstateAI | 16/9/2025 | 30/9/2026 | Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section. | |
| Aplazada | Alta (7.1) | 0.13% | — | Dactum Clickbank Niche StorefrontsAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in dactum Clickbank WordPress Plugin (Niche Storefront) clickbank-niche-storefronts allows Stored XSS.This issue affects Clickbank WordPress Plugin (Niche Storefront): from n/a through <= 1.3.5. | |
| Aplazada | Alta (7.1) | 0.12% | — | Offclicks Invisible OptinAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OffClicks Invisible Optin invisible-optin allows Stored XSS.This issue affects Invisible Optin: from n/a through <= 1.0. | |
| Aplazada | Crítica (9.8) | 0.44% | — | Disable-right-click-powered-by-pixtermeAIPixter-image-digital-licenseAI | 14/8/2025 | 17/6/2026 | The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security… | |
| Aplazada | Crítica (9.8) | 0.36% | — | Clickandpledge Click AND Pledge ConnectAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects Click & Pledge Connect: from 25.04010101 through WP6.8. | |
| Analizada | Alta (7.1) | 0.46% | — | 4pace Cadclick | 25/6/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web script or HTML via the "tree" parameter. | |
| Aplazada | Media (6.5) | 0.19% | — | Wp-kama Kama Click CounterAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timur Kamaev Kama Click Counter kama-clic-counter allows Stored XSS.This issue affects Kama Click Counter: from n/a through <= 4.0.3. | |
| Aplazada | Media (6.4) | 0.27% | — | Click TO ChatAI | 14/6/2025 | 17/6/2026 | The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter in all versions up to, and including, 4.22 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Crítica (9.3) | 0.43% | — | Clickandpledge Click Pledge WpjobboardAI | 10/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge WordPress-WPJobBoard click-pledge-wpjobboard allows Blind SQL Injection.This issue affects WordPress-WPJobBoard: from n/a through <= 25.07010000-WP6.8.1-JB5.11.5. | |
| Aplazada | Media (6.5) | 0.24% | — | History LOG BY Click5AI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in click5 History Log by click5 history-log-by-click5 allows Stored XSS.This issue affects History Log by click5: from n/a through <= 1.0.13. | |
| Aplazada | Alta (8.7) | 0.36% | — | ClickeduAI | 26/5/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in Clickedu. This vulnerability could allow an attacker to retrieve information about student report cards. | |
| Analizada | Alta (8.2) | 0.88% | — | Clickhouse | 21/5/2025 | 17/6/2026 | Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3. | |
| Aplazada | Alta (7.5) | 0.55% | — | Indie Plugins Whatsapp Click TO ChatAI | 19/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Indie_Plugins WhatsApp Click to Chat Plugin for WordPress wpt-whatsapp.This issue affects WhatsApp Click to Chat Plugin for WordPress: from n/a through <= 2.2.12. | |
| Analizada | Media (4.8) | 0.34% | — | Clicksold IDX | 15/5/2025 | 17/6/2026 | The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.30% | — | Wp-buy WP Content Copy Protection & NO Right Click | 15/5/2025 | 17/6/2026 | The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (6.1) | 0.52% | 💥 Exploit | Wp-buy WP Content Copy Protection & NO Right Click | 15/5/2025 | 17/6/2026 | The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites | |
| Aplazada | Alta (8.8) | 1.6% | — | 1click Wordpress Migration 1 Click Wordpress MigrationAI | 9/5/2025 | 17/6/2026 | The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'start_restore' function in all versions up to, and including, 2.2. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.37% | — | Flowdee Clickwhale | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ClickWhale ClickWhale clickwhale allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ClickWhale: from n/a through <= 2.4.6. | |
| Aplazada | Alta (7.1) | 0.19% | — | Awplife Right Click Disable OR BANAI | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban right-click-disable-or-ban allows Stored XSS.This issue affects Right Click Disable OR Ban: from n/a through <= 1.1.17. | |
| Analizada | Media (5.9) | 0.38% | — | Clickhouse CH | 11/4/2025 | 17/6/2026 | When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream. | |
| Aplazada | Alta (7.2) | 0.51% | — | Clickandpledge Click AND Pledge ConnectAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect Plugin allows SQL Injection. This issue affects Click & Pledge Connect Plugin: from 2.24080000 through WP6.6.1. | |
| Aplazada | Media (5.3) | 0.82% | 💥 Exploit | 1clickmigration 1 Click Wordpress MigrationAI | 4/4/2025 | 17/6/2026 | Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Click WordPress Migration: from n/a through <= 2.5.7. | |
| Aplazada | Media (5.4) | 0.49% | — | TIM Nguyen 1-click Backup Restore DatabaseAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Tim Nguyen 1-Click Backup & Restore Database 1-click-backup-restore-database-by-sunbytes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 1-Click Backup & Restore Database: from n/a through <= 1.0.3. |