Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.63% | — | Yithemes Yith Maintenance Mode | 27/9/2021 | 17/6/2026 | Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yith_maintenance_newsletter_submit_label. Possible even when unfiltered HTML is disallowed by WordPress configuration. | |
| Modificada | Alta (8.8) | 1.3% | — | Wpshopmart Coming Soon Page & Maintenance Mode | 14/5/2021 | 17/6/2026 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps… | |
| Modificada | Media (5.4) | 3.8% | 💥 Exploit | Seedprod Coming Soon Page, Under Construction & Maintenance Mode | 24/6/2020 | 17/6/2026 | The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS. | |
| Modificada | Alta (7.6) | 2.0% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 9/1/2020 | 17/6/2026 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting). | |
| Modificada | Media (5.4) | 1.1% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 9/1/2020 | 17/6/2026 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes. | |
| Modificada | Alta (8.8) | 0.92% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 9/1/2020 | 17/6/2026 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo. | |
| Modificada | Media (6.5) | 0.87% | — | Yithemes Yith Maintenance Mode | 26/9/2019 | 17/6/2026 | The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter. | |
| Modificada | Alta (7.2) | 1.5% | — | Designmodo WP Maintenance Mode | 14/12/2018 | 17/6/2026 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network. | |
| Modificada | Media (4.3) | 0.78% | — | Designmodo WP Maintenance Mode | 14/12/2018 | 17/6/2026 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings. | |
| Modificada | Media (4.3) | 0.98% | — | Designmodo WP Maintenance Mode | 14/12/2018 | 17/6/2026 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses. | |
| Modificada | Media (6.8) | 0.95% | — | Wordpress WP Maintenance Mode Plugin | 21/6/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings. |