Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.40% | — | Utopique Better Comments | 24/4/2024 | 17/6/2026 | The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (4.3) | 0.34% | — | Genialsouls WP Social CommentsAI | 18/4/2024 | 17/6/2026 | Missing Authorization vulnerability in GenialSouls WP Social Comments.This issue affects WP Social Comments: from n/a through 1.7.3. | |
| Aplazada | Alta (7.6) | 0.52% | — | Wpzest Disable CommentsAI | 15/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPZest Disable Comments | WPZest.This issue affects Disable Comments | WPZest: from n/a through 1.51. | |
| Aplazada | Media (4.3) | 0.23% | — | Webtoffee Wordpress Comments Import ExportAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.5. | |
| Modificada | Alta (7.5) | 0.51% | — | Wpkube Subscribe TO Comments Reloaded | 10/4/2024 | 12/8/2026 | Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725. | |
| Aplazada | Media (6.5) | 0.33% | — | Sayandatta Ultimate Social Comments Email Notification Lazy LoadAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayan Datta Ultimate Social Comments – Email Notification & Lazy Load allows Stored XSS.This issue affects Ultimate Social Comments – Email Notification & Lazy Load: from n/a through 1.4.8. | |
| Modificada | Media (5.4) | 0.34% | — | Heateor Fancy Comments | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Fancy Comments WordPress allows Stored XSS.This issue affects Fancy Comments WordPress: from n/a through 1.2.14. | |
| Analizada | Crítica (9.8) | 0.83% | — | Sunnytoo Product Comments | 14/3/2024 | 17/6/2026 | SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method. | |
| Analizada | Media (4.3) | 0.30% | — | Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT | 13/3/2024 | 11/8/2026 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on several ajax actions. This makes it possible for unauthenticated attackers to invoke those actions via a… | |
| Analizada | Media (4.3) | 0.53% | — | Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT | 13/3/2024 | 11/8/2026 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0. This is due to missing or incorrect capability checks on several ajax actions. This makes it possible for authenticated attackers, with subscriber access or higher, to… | |
| Modificada | Alta (8.8) | 0.27% | — | Gvectors Woodiscuz - Woocommerce Comments | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0. | |
| Modificada | Crítica (9.8) | 0.85% | — | Webtoffee Wordpress Comments Import AND Export | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.1. | |
| Modificada | Media (4.8) | 0.32% | — | Pixelgrade Comments Rating | 6/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions. | |
| Modificada | Crítica (9.8) | 0.55% | — | Appjetty Copy OR Move Comments | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in biztechc Copy or Move Comments allows SQL Injection.This issue affects Copy or Move Comments: from n/a through 5.0.4. | |
| Modificada | Media (6.1) | 0.39% | — | Appjetty Copy OR Move Comments | 25/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Biztechc Copy or Move Comments plugin <= 5.0.4 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Pixelgrade Comments Rating | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions. | |
| Modificada | Media (4.3) | 0.93% | 💥 PoC | Wphappycoders Comments Like Dislike | 17/8/2023 | 17/6/2026 | The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers with minimal permissions, such as a… | |
| Modificada | Media (4.3) | 0.56% | — | Vuukle Comments, Reactions, Share Bar, Revenue | 12/7/2023 | 17/6/2026 | The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wordpress-vuukle-admin-display.php file. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.26% | — | Pixelgrade Comments Rating | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.6 versions. | |
| Modificada | Media (5.3) | 0.46% | — | Palantir Foundry Comments | 10/7/2023 | 17/6/2026 | A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0. | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Heator Social Share, Social Login AND Social Comments | 19/6/2023 | 17/6/2026 | The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Crítica (9.8) | 2.3% | — | Delete ALL Comments Project Delete ALL Comments | 7/6/2023 | 17/6/2026 | The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-comments.php file in versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which… | |
| Modificada | Media (6.5) | 0.54% | — | Palantir Foundry Comments | 6/6/2023 | 17/6/2026 | A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorization checks. This could enable an authenticated user to inject a prior discovered attachment UUID into other arbitrary comments to discover it's content. This defect was… | |
| Modificada | Media (4.8) | 0.37% | — | Gvectors Woodiscuz - Woocommerce Comments | 28/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.2.9. | |
| Modificada | Media (4.8) | 0.37% | — | Lazy Social Comments Project Lazy Social Comments | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Lazy Social Comments plugin <= 2.0.4 versions. |