Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

127 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.40%—Utopique Better Comments24/4/202417/6/2026
The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaMedia (4.3)0.34%—Genialsouls WP Social CommentsAI18/4/202417/6/2026
Missing Authorization vulnerability in GenialSouls WP Social Comments.This issue affects WP Social Comments: from n/a through 1.7.3.
AplazadaAlta (7.6)0.52%—Wpzest Disable CommentsAI15/4/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPZest Disable Comments | WPZest.This issue affects Disable Comments | WPZest: from n/a through 1.51.
AplazadaMedia (4.3)0.23%—Webtoffee Wordpress Comments Import ExportAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.5.
ModificadaAlta (7.5)0.51%—Wpkube Subscribe TO Comments Reloaded10/4/202412/8/2026
Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.
AplazadaMedia (6.5)0.33%—Sayandatta Ultimate Social Comments Email Notification Lazy LoadAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayan Datta Ultimate Social Comments – Email Notification & Lazy Load allows Stored XSS.This issue affects Ultimate Social Comments – Email Notification & Lazy Load: from n/a through 1.4.8.
ModificadaMedia (5.4)0.34%—Heateor Fancy Comments27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Fancy Comments WordPress allows Stored XSS.This issue affects Fancy Comments WordPress: from n/a through 1.2.14.
AnalizadaCrítica (9.8)0.83%—Sunnytoo Product Comments14/3/202417/6/2026
SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.
AnalizadaMedia (4.3)0.30%—Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT13/3/202411/8/2026
The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on several ajax actions. This makes it possible for unauthenticated attackers to invoke those actions via a…
AnalizadaMedia (4.3)0.53%—Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT13/3/202411/8/2026
The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0. This is due to missing or incorrect capability checks on several ajax actions. This makes it possible for authenticated attackers, with subscriber access or higher, to…
ModificadaAlta (8.8)0.27%—Gvectors Woodiscuz - Woocommerce Comments18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0.
ModificadaCrítica (9.8)0.85%—Webtoffee Wordpress Comments Import AND Export7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.1.
ModificadaMedia (4.8)0.32%—Pixelgrade Comments Rating6/11/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions.
ModificadaCrítica (9.8)0.55%—Appjetty Copy OR Move Comments6/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in biztechc Copy or Move Comments allows SQL Injection.This issue affects Copy or Move Comments: from n/a through 5.0.4.
ModificadaMedia (6.1)0.39%—Appjetty Copy OR Move Comments25/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Biztechc Copy or Move Comments plugin <= 5.0.4 versions.
ModificadaAlta (8.8)0.21%—Pixelgrade Comments Rating16/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions.
ModificadaMedia (4.3)0.93%💥 PoCWphappycoders Comments Like Dislike17/8/202317/6/2026
The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers with minimal permissions, such as a…
ModificadaMedia (4.3)0.56%—Vuukle Comments, Reactions, Share Bar, Revenue12/7/202317/6/2026
The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wordpress-vuukle-admin-display.php file. This makes it possible for…
ModificadaAlta (8.8)0.26%—Pixelgrade Comments Rating11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.6 versions.
ModificadaMedia (5.3)0.46%—Palantir Foundry Comments10/7/202317/6/2026
A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.
ModificadaMedia (6.1)6.0%💥 ExploitHeator Social Share, Social Login AND Social Comments19/6/202317/6/2026
The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaCrítica (9.8)2.3%—Delete ALL Comments Project Delete ALL Comments7/6/202317/6/2026
The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-comments.php file in versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which…
ModificadaMedia (6.5)0.54%—Palantir Foundry Comments6/6/202317/6/2026
A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorization checks. This could enable an authenticated user to inject a prior discovered attachment UUID into other arbitrary comments to discover it's content. This defect was…
ModificadaMedia (4.8)0.37%—Gvectors Woodiscuz - Woocommerce Comments28/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.2.9.
ModificadaMedia (4.8)0.37%—Lazy Social Comments Project Lazy Social Comments9/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Lazy Social Comments plugin <= 2.0.4 versions.
Orbitaley — Vulnerabilidades