Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.25% | — | Category Dropdown ListAI | 12/12/2025 | 17/6/2026 | The Category Dropdown List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.4) | 0.28% | — | WP DropzoneAI | 12/12/2025 | 17/6/2026 | The WP Dropzone plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callback' shortcode attribute in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on user-supplied 'callback' attributes, which are evaluated as JavaScript code via the… | |
| Aplazada | Media (4.3) | 0.22% | — | Eprolo DropshippingAI | 5/12/2025 | 25/9/2026 | The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_eprolo_delete_tracking and wp_ajax_eprolo_save_tracking_data AJAX endpoints in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag Drop Form BuilderAI | 2/12/2025 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12.20. This is due to missing nonce validation on the SurveyJS_DeleteSurvey AJAX action. This makes it possible for unauthenticated attackers to delete surveys via a… | |
| Aplazada | Media (5.3) | 0.29% | — | Bigbuy Dropshipping ConnectorAI | 21/11/2025 | 17/6/2026 | The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.5 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated… | |
| Analizada | Media (6.1) | 0.21% | — | Backdropcms Backdrop CMS | 18/11/2025 | 17/6/2026 | Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection. | |
| Aplazada | Alta (8.8) | 0.61% | — | WP DropzoneAI | 18/11/2025 | 17/6/2026 | The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 1.1.0 via the `ajax_upload_handle` function. This is due to the chunked upload functionality writing files directly to the uploads directory before any file type validation occurs. This makes… | |
| Aplazada | Alta (7.1) | 0.22% | — | Jhainey Milevis DropifyAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jhainey Milevis Dropify wc-dropi-integration allows Reflected XSS.This issue affects Dropify: from n/a through <= 4.7.2. | |
| Aplazada | Crítica (10) | 0.43% | — | Borisolhor Drop Uploader FOR CF7AI | 6/11/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploader Addon drop-uploader-for-contact-form-7-dragdrop-file-uploader-addon allows Upload a Web Shell to a Web Server.This issue affects Drop Uploader for CF7 - Drag&Drop File Uploader Addon: from n/a… | |
| Aplazada | Media (6.5) | 0.28% | — | Gcsdesign WP Category DropdownAI | 22/9/2025 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandrika Sista WP Category Dropdown wp-category-dropdown allows Stored XSS.This issue affects WP Category Dropdown: from n/a through <= 1.9. | |
| Aplazada | Crítica (10) | 0.38% | — | Add-ons.org Drag AND Drop File Upload FOR Elementor FormsAI | 28/8/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms drag-and-drop-file-upload-for-elementor-forms allows Upload a Web Shell to a Web Server.This issue affects Drag and Drop File Upload for Elementor Forms: from n/a through <= 1.5.3. | |
| Aplazada | Media (5.3) | 0.71% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 16/8/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticated attackers to upload and delete files outside of the originally intended… | |
| Aplazada | Alta (7.6) | 0.43% | — | Xolluteon DropshixAI | 15/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xolluteon Dropshix allows DOM-Based XSS.This issue affects Dropshix: from n/a through 4.0.14. | |
| Aplazada | Media (5.9) | 0.22% | — | Kadesthemes WP Airdrop ManagerAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kadesthemes WP Airdrop Manager airdrop allows Stored XSS.This issue affects WP Airdrop Manager: from n/a through <= 1.0.5. | |
| Aplazada | Media (6.5) | 0.30% | — | NET DropbearAILibtommathAI | 16/7/2025 | 17/6/2026 | Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net::Dropbear embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328. | |
| Aplazada | Crítica (9.8) | 0.74% | — | Drag AND Drop Multiple File Upload PROAI | 2/7/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dnd_upload_cf7_upload_chunks() function in version 5.0 - 5.0.5 (when bundled with the PrintSpace theme) and all versions up to, and including, 1.7.1 (in the… | |
| Aplazada | Crítica (10) | 0.41% | — | Harutheme Drag AND Drop Multiple File Upload PRO WoocommerceAI | 27/6/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - WooCommerce drag-and-drop-file-upload-wc-pro allows Upload a Web Shell to a Web Server.This issue affects Drag and Drop Multiple File Upload (Pro) - WooCommerce: from n/a through <= 5.0.6. | |
| Modificada | Media (6.1) | 0.21% | — | Backdropcms Backdrop CMS | 26/6/2025 | 5/7/2026 | A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30. | |
| Analizada | Crítica (9.8) | 5.8% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 17/6/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible for unauthenticated attackers to bypass the plugin's blacklist and upload .phar or other… | |
| Aplazada | Alta (8.6) | 1.4% | — | Add-ons.org Drag AND Drop File Upload FOR Elementor FormsAI | 23/5/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms drag-and-drop-file-upload-for-elementor-forms allows Path Traversal.This issue affects Drag and Drop File Upload for Elementor Forms: from n/a through <= 1.4.3. | |
| Aplazada | Baja (2.1) | 0.40% | — | DumbdropAI | 15/5/2025 | 17/6/2026 | DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scripting vulnerability in the upload functionality prior to commit db27b25372eb9071e63583d8faed2111a2b79f1b. A user could be tricked into uploading a file with a malicious payload. Commit… | |
| Aplazada | Crítica (9.8) | 2.3% | — | Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI | 9/5/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supported_type string and the uploaded filename without enforcing real extension or MIME checks within the upload() function.… | |
| Aplazada | Media (4.5) | 0.59% | — | Dropbear SSHAI | 7/5/2025 | 17/6/2026 | dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used. | |
| Aplazada | Media (4.3) | 0.17% | — | Silverplugins217 Product Quantity Dropdown FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Product Quantity Dropdown For Woocommerce product-quantity-dropdown-for-woocommerce allows Cross Site Request Forgery.This issue affects Product Quantity Dropdown For Woocommerce: from n/a through <= 1.2. | |
| Aplazada | Media (6.4) | 0.24% | — | Backdrop FlagAI | 25/4/2025 | 17/6/2026 | An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and any other type of entity. It doesn't verify flag links before performing the flag action, or verify that the response returned was provided by the flag module.… |