Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1811 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.1) | 0.30% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during the import process, allowing users with the import capability, which administrators hold by default, to make the site issue requests to internal hosts and services and read their responses. This is an… | |
| Aplazada | Media (6.8) | 0.43% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database before inserting them into the DOM of one of its administration screens, allowing users with a role as low as contributor to perform Stored XSS attacks which will trigger in the browser of a high… | |
| Aplazada | Media (6.8) | 0.39% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, allowing users whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's import permission to perform SQL… | |
| Aplazada | Media (6.8) | 0.39% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values before using them in SQL statements, allowing users holding its export permission, which administrators have by default and may also grant to lower roles, to perform SQL injection attacks. | |
| Aplazada | Media (6.8) | 0.47% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing any user whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's import permission to disclose… | |
| Aplazada | Media (6.5) | 0.45% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Import Export Lite WordPress plugin before 3.9.33 capability to delete arbitrary… | |
| Aplazada | Alta (8.8) | 0.73% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL during import, allowing users granted its import permission to store arbitrary files, including executable ones, on the server and achieve remote code execution. | |
| Aplazada | Alta (7.2) | 0.82% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted its export permission to have arbitrary functions invoked on values they control, leading to remote code execution. | |
| Aplazada | Alta (7.2) | 0.82% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing export files, allowing users granted its export permission to write files with arbitrary names to arbitrary locations on the server, leading to remote code execution. | |
| Aplazada | Alta (7.2) | 0.25% | — | Wp-lister Lite WP Lister LiteAI | 16/9/2026 | 16/9/2026 | The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Request Parameter in all versions up to, and including, 3.8.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (4.4) | 0.19% | — | Outerbase StudioAIPostgresqlAIMysqlAISqliteAI | 15/9/2026 | 30/9/2026 | Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangerouslySetInnerHTML, allowing injected markup with script-capable event handlers to… | |
| Aplazada | Alta (7.5) | 0.97% | — | AnyqueryAIHashicorp Go-getterAISqliteAI | 14/9/2026 | 30/9/2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions. A remote attacker can use SQLite CREATE… | |
| Aplazada | Crítica (9.1) | 0.97% | — | AnyqueryAISqliteAI | 14/9/2026 | 30/9/2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacker can select any path writable by the Anyquery server process, cause SQLite to… | |
| Aplazada | Media (4.8) | 0.37% | — | Linlinjava LitemallAI | 13/9/2026 | 16/9/2026 | A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leads to cross site scripting. The attack… | |
| Aplazada | Media (4.8) | 0.37% | — | Linlinjava LitemallAI | 13/9/2026 | 14/9/2026 | A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. This manipulation causes cross site scripting. The attack may be initiated remotely.… | |
| Aplazada | Media (6.4) | 0.36% | — | Bold-themes Bold Timeline LiteAI | 11/9/2026 | 11/9/2026 | The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Alta (7.1) | 0.25% | — | Page Visits Counter - LiteAI | 10/9/2026 | 10/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions. | |
| Aplazada | Alta (7.2) | 0.27% | — | Litespeedtech Litespeed CacheAI | 3/9/2026 | 4/9/2026 | Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Joodatabase LiteAI | 3/9/2026 | 3/9/2026 | Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors. | |
| Pendiente de análisis | Media (6.5) | 0.54% | — | LitellmAI | 2/9/2026 | 9/9/2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured provider credentials to that… | |
| Aplazada | Baja (2.1) | 0.20% | — | Ash-project ASH SqliteAI | 30/8/2026 | 1/9/2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested JSON the application never exposed, disclosing private or sensitive? embedded fields. AshSqlite.SqlImplementation builds the SQLite… | |
| Aplazada | Media (6.4) | 0.33% | — | Litespeedtech Litespeed CacheAI | 28/8/2026 | 29/8/2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images" and "Add Missing… | |
| Aplazada | Alta (7.2) | 0.37% | — | Litespeedtech Litespeed CacheAI | 28/8/2026 | 28/8/2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Crítica (9.8) | 0.80% | — | LitellmAI | 27/8/2026 | 1/9/2026 | BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment. | |
| Analizada | Media (6.1) | 0.58% | — | Dangerblack N8n-node-sqlite3 | 27/8/2026 | 23/9/2026 | n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workflow input. A workflow author who maps untrusted input to db_path can allow a… |