Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Uniconsent CMP FOR Gdpr Cpra GPP TCF | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in UniConsent UniConsent CMP for GDPR CPRA GPP TCF plugin <= 1.4.2 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Radicalwebdesign Gdpr Cookie Consent Notice BOX | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Radical Web Design GDPR Cookie Consent Notice Box plugin <= 1.1.6 versions. | |
| Modificada | Media (6.5) | 0.32% | — | Mooveagency Gdpr Cookie Compliance | 30/8/2023 | 17/6/2026 | The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks | |
| Modificada | Media (6.1) | 0.66% | — | Createit Ultimate Gdpr & Ccpa Compliance Toolkit | 7/6/2023 | 17/6/2026 | The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export_settings & import_settings functions in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to change plugin settings and conduct attacks such as redirecting… | |
| Modificada | Media (6.5) | 0.85% | — | Appsaloon WP Gdpr | 7/6/2023 | 17/6/2026 | The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to delete any comment and modify the plugin’s settings. | |
| Modificada | Media (4.3) | 0.70% | — | Mooveagency Gdpr Cookie Compliance | 7/6/2023 | 17/6/2026 | The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. This makes it possible for authenticated attackers to reset all of the settings. | |
| Modificada | Alta (8.8) | 0.27% | — | Stylemixthemes Gdpr Compliance & Cookie Consent | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes GDPR Compliance & Cookie Consent plugin <= 1.2 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Surbma Gdpr Proof Cookie Consent & Notice BAR | 8/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Surbma Surbma | GDPR Proof Cookie Consent & Notice Bar plugin <= 17.5.3 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Hu-manity Cookie Notice & Compliance FOR Gdpr / Ccpa | 7/5/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Hu-manity.Co Cookie Notice & Compliance for GDPR / CCPA plugin <= 2.4.6 versions. | |
| Modificada | Media (5.4) | 0.46% | — | Hu-manity Cookie Notice & Compliance FOR Gdpr / Ccpa | 27/3/2023 | 17/6/2026 | The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.4.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Crítica (9.1) | 2.6% | 💥 Exploit | Lineagrafica EU Cookie LAW Gdpr | 10/11/2022 | 17/6/2026 | The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ). | |
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Cookieinformation Wp-gdpr-compliance | 14/3/2022 | 17/6/2026 | The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Welaunch Wordpress Gdpr&ccpa | 1/2/2022 | 17/6/2026 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this… | |
| Modificada | Crítica (9.6) | 2.1% | — | Welaunch Wordpress Gdpr&ccpa | 1/2/2022 | 17/6/2026 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this… | |
| Modificada | Media (4.8) | 0.56% | — | Tarteaucitron.js - Cookies Legislation & Gdpr Project Tarteaucitron.js - Cookies Legislation & Gdpr | 20/12/2021 | 17/6/2026 | Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.6). | |
| Modificada | Alta (8.8) | 0.49% | — | Tarteaucitron.js - Cookies Legislation & Gdpr Project Tarteaucitron.js - Cookies Legislation & Gdpr | 20/12/2021 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitronEmail" and "tarteaucitronPass". | |
| Modificada | Media (4.8) | 0.62% | — | Hu-manity Cookie Notice & Compliance FOR Gdpr / Ccpa | 27/9/2021 | 17/6/2026 | The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Text setting when outputting it in an attribute in the frontend, allowing high privilege users such as admin to perform Cross-Site Scripting even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 0.62% | — | Gdprinfo Cookie Notice & Consent Banner FOR Gdpr & Ccpa Compliance | 6/9/2021 | 17/6/2026 | The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customization options. | |
| Modificada | Media (6.1) | 0.94% | — | Appsaloon Wp-gdpr | 31/8/2020 | 17/6/2026 | controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS. | |
| Modificada | Media (5.4) | 0.86% | — | Cookielawinfo Gdpr Cookie Consent | 21/8/2020 | 17/6/2026 | ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation. | |
| Modificada | Crítica (9.8) | 88% | 💥 Exploit | Van-ons Wp-gdpr-compliance | 12/11/2018 | 17/6/2026 | The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018. |