Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.24% | — | Hashthemes Demo ImporterAI | 23/7/2026 | 23/7/2026 | Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Really Simple CSV ImporterAI | 23/7/2026 | 23/7/2026 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | |
| Aplazada | Media (4.3) | 0.43% | — | Catchthemes Catch Themes Demo ImportAI | 16/7/2026 | 17/7/2026 | The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activate_plugin GET parameter is present, calling Plugin_Upgrader::install() to download… | |
| Aplazada | Alta (8.8) | 1.1% | — | Smackcoders WP Ultimate CSV ImporterAI | 11/7/2026 | 13/7/2026 | The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and… | |
| Aplazada | Media (4.4) | 0.24% | — | WP Ultimate CSV Importer Infinite Scroll Ajax Load MoreAI | 10/7/2026 | 14/7/2026 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Media (4.3) | 0.39% | — | Codection Import AND Export Users AND CustomersAI | 10/7/2026 | 10/7/2026 | The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw… | |
| Aplazada | Alta (7.2) | 1.1% | — | Post Export Import With MediaAI | 10/7/2026 | 10/7/2026 | The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure function. This is due to insufficient file extension validation caused by a trailing-dot filename bypass, where the extension allow-list check in… | |
| Aplazada | Baja (2.1) | 0.23% | — | Assimp Open Asset Import LibraryAI | 3/7/2026 | 6/7/2026 | A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file code/AssetLib/Ply/PlyLoader.cpp of the component PLY Model Handler. This manipulation causes double free. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.39% | — | Vjinfotech WP Import Export LiteAI | 3/7/2026 | 6/7/2026 | The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url AJAX action. The plugin's URL downloader first calls wp_safe_remote_get() (which correctly blocks private/reserved IP ranges), but when that… | |
| Aplazada | Alta (7.6) | 0.38% | — | Wpallimport WP ALL ImportAI | 26/6/2026 | 26/6/2026 | Administrator SQL Injection in WP All Import <= 4.0.1 versions. | |
| Aplazada | Alta (8.8) | 0.37% | — | Akin Software Computer Import Export Industry AND Trade LTD CafeplusAI | 23/6/2026 | 23/6/2026 | Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects CafePlus: from 12.05.03 before 12.05.04. | |
| Aplazada | Media (6.4) | 0.34% | — | Addonspress Advanced ImportAI | 19/6/2026 | 22/6/2026 | The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() to fetch a user-supplied URL without validating that the URL does not point to internal or private network resources in the… | |
| Analizada | Media (4.3) | 0.28% | — | Jenkins JOB Import | 27/5/2026 | 17/6/2026 | Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Aplazada | Media (4.3) | 0.29% | — | Webtoffee Product Import Export FOR WoocommerceAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Export for WooCommerce: from n/a through 2.5.6. | |
| Aplazada | Media (4.3) | 0.26% | — | Gsheet FOR WOO ImporterAI | 21/5/2026 | 23/7/2026 | The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Aplazada | Media (6.1) | 0.36% | — | LJ Comments Import ReloadedAI | 20/5/2026 | 23/7/2026 | The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (8.7) | 0.61% | — | Woocommerce CSV ImporterAI | 17/5/2026 | 17/6/2026 | Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX action. Attackers can craft POST requests with directory traversal sequences in the filename parameter to delete… | |
| Aplazada | Media (5.3) | 0.33% | — | Magic Export & ImportAI | 4/5/2026 | 17/6/2026 | The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making it possible for any visitors to leak sensitive user information. | |
| Aplazada | Alta (8.8) | 0.72% | — | Codection Import AND Export Users AND CustomersAI | 2/5/2026 | 17/6/2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary site (e.g.,… | |
| Aplazada | Media (6.8) | 0.12% | — | RoboimportAI | 26/4/2026 | 17/6/2026 | RoboImport 1.2.0.72 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to registration fields. Attackers can paste a 6000-byte buffer into the Registration Name and Registration Key fields and click Register to trigger an application crash. | |
| Aplazada | Media (5.3) | 0.31% | — | Themegrill Demo ImporterAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeGrill Demo Importer: from n/a through <= 2.0.0.6. | |
| Aplazada | Alta (7.7) | 0.39% | — | Webtoffee Comments Import AND Export WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comments Import & Export: from n/a through <= 2.4.9. | |
| Aplazada | Alta (8.1) | 0.54% | 💥 PoC | Codection Import AND Export Users AND CustomersAI | 21/3/2026 | 17/6/2026 | The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields'… | |
| Analizada | Media (6.9) | 0.17% | — | Cewe Photo Importer | 21/3/2026 | 17/6/2026 | CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing… | |
| Analizada | Crítica (9.9) | 0.59% | 💥 PoC | Apostrophecms Import-export | 18/3/2026 | 17/6/2026 | ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths using `fs.createWriteStream(path.join(exportPath, header.name))`. `path.join()` does not resolve or sanitise traversal segments such… |