Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.15% | — | Easy Twitter FeedsAI | 10/6/2026 | 23/7/2026 | Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into visiting a crafted link that duplicates any post regardless of post type. | |
| Aplazada | Media (4.3) | 0.49% | — | Feedzy RSS AggregatorAI | 6/6/2026 | 23/7/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Media (4.3) | 0.15% | — | Bplugins Tiktok FeedAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tiktok Feed: from n/a through 1.0.24. | |
| Aplazada | Media (5.4) | 0.32% | — | Smashballoon Feeds FOR YoutubeAI | 18/5/2026 | 17/6/2026 | The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4's license key due to a missing capability check on the 'actions' function. This… | |
| Aplazada | Alta (7.2) | 0.51% | — | Smashballoon Custom Twitter FeedsAI | 13/5/2026 | 17/6/2026 | The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's ctf_get_more_posts AJAX action is available… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Feedback SystemAI | 7/5/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the file /admin/checklogin.php. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.4) | 0.32% | — | MY Social FeedsAI | 2/5/2026 | 17/6/2026 | The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 1.0.4 via the 'ttp_get_accounts' AJAX action. This is due to the complete absence of authorization checks (no capability verification) and nonce verification in the… | |
| Aplazada | Media (6.5) | 0.83% | 💥 Exploit | Trustindex Widgets FOR Social Photo FeedAI | 2/5/2026 | 7/10/2026 | The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and… | |
| Aplazada | Media (4.3) | 0.27% | — | Syedbalkhi User FeedbackAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through <= 1.10.1. | |
| Aplazada | Alta (7.6) | 0.36% | — | Syedbalkhi User FeedbackAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through <= 1.10.1. | |
| Aplazada | Alta (8.8) | 0.21% | — | Adtribes Product Feed PROAI | 8/4/2026 | 24/7/2026 | The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 13.4.6 through 13.5.2.1. This is due to missing or incorrect nonce validation on the ajax_migrate_to_custom_post_type,… | |
| Analizada | Alta (7.5) | 0.50% | 💥 PoC | Kagi Fastfeedparser | 7/4/2026 | 24/7/2026 | FastFeedParser is a high performance RSS, Atom and RDF parser. Prior to 0.5.10, when parse() fetches a URL that returns an HTML page containing a <meta http-equiv="refresh"> tag, it recursively calls itself with the redirect URL — with no depth limit, no visited-URL deduplication, and no redirect count cap. An… | |
| Aplazada | Alta (7.2) | 0.39% | — | Widgets FOR Social Photo FeedAI | 4/4/2026 | 24/7/2026 | The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Baja (2.1) | 0.35% | — | Sourcecodester RSS Feed ParserAI | 30/3/2026 | 17/6/2026 | A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Aplazada | Alta (8.1) | 0.40% | — | Jwsthemes FeedyAI | 25/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Feedy feedy allows PHP Local File Inclusion.This issue affects Feedy: from n/a through < 2.1.5. | |
| Aplazada | Alta (7.2) | 0.50% | — | Webtoffee Product Feed FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Object Injection.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.3. | |
| Aplazada | Media (6.1) | 0.43% | — | Alfie Feed PluginAI | 21/3/2026 | 17/6/2026 | The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the alfie_option_page() function combined with insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (6.4) | 0.19% | — | Twitter FeedsAI | 21/3/2026 | 17/6/2026 | The Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tweet_title' parameter in the 'TwitterFeeds' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.1) | 0.17% | — | Invelity Product FeedsAI | 21/3/2026 | 17/6/2026 | The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1.2.6. This is due to missing validation and sanitization in the 'createManageFeedPage' function. This makes it possible for authenticated administrator-level attackers to… | |
| Aplazada | Media (6.5) | 0.17% | — | Josh Kohlbach WOO Product Feed PROAI | 13/3/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Josh Kohlbach Product Feed PRO for WooCommerce woo-product-feed-pro allows Cross Site Request Forgery.This issue affects Product Feed PRO for WooCommerce: from n/a through <= 13.5.2. | |
| Aplazada | Baja (2.3) | 0.21% | — | Mendi Neurofeedback Headset V4AI | 7/3/2026 | 16/8/2026 | A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of the component Bluetooth Low Energy Handler. Performing a manipulation results in cleartext transmission of sensitive information. The attack can only be performed from the local network. The… | |
| Aplazada | Media (4.3) | 0.13% | — | Guardian News FeedAI | 7/3/2026 | 17/6/2026 | The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the Guardian… | |
| Aplazada | Alta (7.1) | 0.24% | — | Keeswolters Mopinion Feedback FormAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keeswolters Mopinion Feedback Form mopinion-feedback-form allows DOM-Based XSS.This issue affects Mopinion Feedback Form: from n/a through <= 1.1.1. | |
| Aplazada | Alta (7.1) | 0.24% | — | BAS Schuiling Feedwordpress Advanced FiltersAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bas Schuiling FeedWordPress Advanced Filters faf allows Reflected XSS.This issue affects FeedWordPress Advanced Filters: from n/a through <= 0.6.2. | |
| Aplazada | Alta (7.2) | 0.85% | — | Webappick CTX FeedAI | 19/2/2026 | 17/6/2026 | The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated attackers, with Shop… |