Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
289 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.6) | 0.50% | — | Ninjateam FastdupAI | 15/6/2026 | 17/6/2026 | Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Aman Views FOR Ninja FormsAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend views-for-ninja-forms allows Blind SQL Injection.This issue affects Ninja Forms Views – Display & Edit Ninja… | |
| Aplazada | Media (5.1) | 0.19% | — | Commoninja Videos Sync PDFAI | 10/5/2026 | 17/6/2026 | WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting unsanitized mov, pdf, mp4, webm, and ogg parameters. Attackers can inject payloads like autofocus onfocus event handlers through the plugin options… | |
| Aplazada | Media (4.3) | 0.25% | — | Wpmanageninja Ninja TablesAI | 6/5/2026 | 17/6/2026 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in all versions up to, and including, 5.2.6. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (6.4) | 0.33% | — | Charts NinjaAI | 5/5/2026 | 17/6/2026 | The Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'chartid' shortcode attribute in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Crítica (9.8) | 63% | 💥 Exploit | Ninjaforms Ninja Forms File UploadsAI | 7/4/2026 | 17/6/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on… | |
| Analizada | Alta (7.7) | 0.37% | — | Invoiceninja Invoice Ninja | 30/3/2026 | 17/6/2026 | Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php. | |
| Aplazada | Media (6.5) | 0.22% | — | Ninjaforms Ninja FormsAI | 28/3/2026 | 17/6/2026 | The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the admin_enqueue_scripts action handler in blocks/bootstrap.php. This makes it possible for authenticated… | |
| Analizada | Media (5.4) | 0.25% | — | Invoiceninja Invoice Ninja | 26/3/2026 | 17/6/2026 | Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fields in Invoice Ninja v5.13.0 allow raw HTML via Markdown rendering, enabling stored XSS. The Markdown parser output was not sanitized with `purify::clean()` before being included in invoice templates.… | |
| Analizada | Media (5.4) | 0.30% | — | Invoiceninja Invoice Ninja | 26/3/2026 | 17/6/2026 | Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item descriptions in Invoice Ninja v5.13.0 bypass the XSS denylist filter, allowing stored XSS payloads to execute when invoices are rendered in the PDF preview or client portal. The line item description… | |
| Pendiente de análisis | Crítica (10) | 0.44% | — | Dendibakh Perf-ninjaAI | 24/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modules). This vulnerability is associated with program files ldo.C. This issue affects perf-ninja. | |
| Analizada | Media (4.3) | 0.31% | — | Jenkins Loadninja | 18/3/2026 | 17/6/2026 | Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| Analizada | Media (4.3) | 0.19% | — | Jenkins Loadninja | 18/3/2026 | 17/6/2026 | Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Aplazada | Alta (7.1) | 0.24% | — | Wpmageninja Fluent CartAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja FluentCart fluent-cart allows Reflected XSS.This issue affects FluentCart: from n/a through < 1.3.0. | |
| Aplazada | Media (4.3) | 0.22% | — | Wpmanageninja Ninja TablesAI | 19/2/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Retrieve Embedded Sensitive Data.This issue affects Ninja Tables: from n/a through <= 5.2.5. | |
| Aplazada | Alta (8.8) | 0.28% | — | Ninjateam FastdupAI | 12/2/2026 | 17/6/2026 | The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (7.5) | 0.35% | — | Ninjaforms Ninja FormsAI | 10/2/2026 | 17/6/2026 | The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags… | |
| Aplazada | Media (6.5) | 0.30% | — | Ninjateam Gdpr Ccpa Compliance SupportAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GDPR CCPA Compliance Support: from n/a through <= 2.7.4. | |
| Aplazada | Media (5.4) | 0.25% | 💥 PoC | Ninjateam WP Duplicate PageAI | 13/1/2026 | 17/6/2026 | The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'duplicateBulkHandle' and 'duplicateBulkHandleHPOS' functions in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (6.5) | 0.29% | — | Wpmanageninja Fluent SupportAI | 8/1/2026 | 7/10/2026 | Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through <= 1.10.4. | |
| Aplazada | Baja (2) | 0.26% | — | InvoiceninjaAI | 7/1/2026 | 17/6/2026 | A security vulnerability has been detected in invoiceninja up to 5.12.38. The affected element is the function copy of the file /app/Jobs/Util/Import.php of the component Migration Import. The manipulation of the argument company_logo leads to server-side request forgery. It is possible to initiate the attack… | |
| Aplazada | Alta (8.5) | 0.24% | — | Wpmanageninja Ninja TablesAI | 6/1/2026 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Blind SQL Injection.This issue affects Ninja Tables: from n/a through <= 5.2.4. | |
| Aplazada | Media (6.5) | 0.38% | — | Ninjateam FastdupAI | 6/1/2026 | 17/6/2026 | The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.7 via the 'dir_path' parameter in the 'njt-fastdup/v1/template/directory-tree' REST API endpoint. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.3) | 0.35% | — | Ninjaforms Ninja Forms | 2/1/2026 | 17/6/2026 | The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions. | |
| Aplazada | Media (6.5) | 0.23% | — | Mahmudul Hasan Arif WP Social NinjaAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Mahmudul Hasan Arif WP Social Ninja wp-social-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Social Ninja: from n/a through <= 3.20.1. |