Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

188 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.15%—Image Optimizer BY WPS SKAI5/12/202517/6/2026
The Image Optimizer by wps.sk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the imagopby_ajax_optimize_gallery() function. This makes it possible for unauthenticated attackers to trigger bulk…
AplazadaMedia (6.4)0.29%—AutoptimizeAI3/12/202517/6/2026
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, 3.1.13 due to insufficient input sanitization and output escaping on user-supplied image attributes in the "create_img_preload_tag" function. This makes it…
AplazadaAlta (8.4)0.12%—Axis OptimizerAIMicrosoft WindowsAI11/11/202517/6/2026
AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can only be exploited if the attacker has access to the local Windows machine and sufficient access rights (administrator) to write…
AnalizadaAlta (7.3)0.23%—Linshenkx Prompt Optimizer6/11/202517/6/2026
A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer v1.3.0 to v1.4.2 allows attackers to scan internal resources via a crafted request.
AplazadaAlta (7.5)0.43%—Processby Lazy Load OptimizerAI6/11/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Processby Lazy Load Optimizer lazy-load-optimizer allows PHP Local File Inclusion.This issue affects Lazy Load Optimizer: from n/a through <= 1.4.7.
AplazadaMedia (4.3)0.20%—Nginxcacheoptimizer Nginx Cache OptimizerAI24/10/202517/6/2026
The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nginxcacheoptimizer-blacklist-update' AJAX action in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaMedia (5.4)0.31%—Shortpixel Image OptimizerAI18/10/202517/6/2026
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authenticated attackers,…
AplazadaMedia (4.3)0.14%—Optimize MoreAI3/10/202517/6/2026
The Optimize More! – CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the reset_plugin function. This makes it possible for unauthenticated attackers to reset the plugin's optimization settings via…
AplazadaMedia (5.4)0.14%—Pl4g4 Wp-database-optimizer-toolsAI14/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools wp-database-optimizer-tools allows Cross Site Request Forgery.This issue affects WP-Database-Optimizer-Tools: from n/a through <= 0.2.
AplazadaMedia (4.8)0.34%—Optimizely Episerver CMS CoreAIOptimizely Episerver CMS UIAI28/7/202517/6/2026
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. RTE properties (text fields), which could be used in the "Edit" section of the…
AplazadaMedia (4.6)0.36%—Optimizely Episerver CMS CoreAIOptimizely Episerver CMS UIAI28/7/202517/6/2026
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. ContentReference properties, which could be used in the "Edit" section of the CMS,…
AplazadaMedia (4.8)0.37%—Optimizely Episerver CMS CoreAIOptimizely Episerver CMS UIAI28/7/202517/6/2026
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. The Admin dashboard offered the functionality to add gadgets to the dashboard.…
AplazadaCrítica (9.6)0.17%—Sh1zen WP OptimizerAI27/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer wp-optimizer allows SQL Injection.This issue affects WP Optimizer: from n/a through <= 2.5.0.
AplazadaCrítica (9.8)0.54%—Pep.vn WP Optimize BY XtrafficAI27/6/202517/6/2026
Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object Injection.This issue affects WP Optimize By xTraffic: from n/a through <= 5.1.6.
AplazadaAlta (7.1)0.26%—Track Analyze AND Optimize BY WP TAOAI17/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michal Jaworski Track, Analyze & Optimize by WP Tao wp-tao allows Reflected XSS.This issue affects Track, Analyze & Optimize by WP Tao: from n/a through <= 1.3.
AnalizadaMedia (4.1)0.32%—Updraftplus Wp-optimize2/6/202517/6/2026
The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.
AplazadaMedia (6.4)0.24%—WP Youtube Video OptimizerAI21/5/202517/6/2026
The WP YouTube Video Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ib_youtube' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaAlta (7.5)0.69%—Capturly-optimize-your-websiteAI24/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Capturly Capturly capturly-optimize-your-website allows PHP Local File Inclusion.This issue affects Capturly: from n/a through <= 2.0.1.
AnalizadaMedia (5.9)0.32%—Drupal 8 Google Optimize Hide Page Project Drupal 8 Google Optimize Hide Page16/4/202517/6/2026
Vulnerability in Drupal Drupal 8 Google Optimize Hide Page.This issue affects Drupal 8 Google Optimize Hide Page: *.*.
AnalizadaMedia (5.9)0.32%—Google Optimize Project Google Optimize16/4/202517/6/2026
Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.
AplazadaAlta (8.8)0.51%—Coothemes Easy WP OptimizerAI4/4/202517/6/2026
Missing Authorization vulnerability in coothemes Easy WP Optimizer easy-wp-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy WP Optimizer: from n/a through <= 1.1.0.
AplazadaMedia (5.3)0.50%—Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI1/4/202517/6/2026
Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Retrieve Embedded Sensitive Data.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through…
AplazadaMedia (4.3)0.14%—Matthewprice1178 WP Database OptimizerAI28/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in matthewprice1178 WP Database Optimizer wp-database-optimizer allows Cross Site Request Forgery.This issue affects WP Database Optimizer: from n/a through <= 1.2.1.3.
AplazadaMedia (5.9)0.23%—Matthewprice1178 WP Database OptimizerAI28/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matthewprice1178 WP Database Optimizer wp-database-optimizer allows Stored XSS.This issue affects WP Database Optimizer: from n/a through <= 1.2.1.3.
AplazadaMedia (5.9)0.21%—Preetindersodhi TGG WP OptimizerAI28/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in preetindersodhi TGG WP Optimizer tgg-wp-optimizer allows Stored XSS.This issue affects TGG WP Optimizer: from n/a through <= 1.25.