Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Microkid Related Posts FOR WordpressAI | 17/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Microkid Related Posts for WordPress allows Cross-Site Scripting (XSS).This issue affects Related Posts for WordPress: from n/a through 4.0.3. | |
| Aplazada | Media (4.3) | 0.20% | — | Data443 Inline Related PostsAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Data443 Inline Related Posts.This issue affects Inline Related Posts: from n/a through 3.3.1. | |
| Analizada | Media (4.3) | 0.45% | — | Data443 Inline Related Posts | 11/4/2024 | 17/6/2026 | The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users are allowed to see the content of the posts displayed, allowing any authenticated user, such as subscriber to retrieve the content of password protected posts | |
| Analizada | Media (4.8) | 0.42% | — | Data443 Inline Related Posts | 6/4/2024 | 17/6/2026 | The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (5.4) | 0.28% | — | Never5 Related Posts | 13/3/2024 | 17/6/2026 | The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handle_create_link() function. This makes it possible for unauthenticated attackers to add related posts to other… | |
| Modificada | Media (4) | 0.51% | — | Yarpp YET Another Related Posts Plugin | 29/2/2024 | 17/6/2026 | The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Modificada | Media (5.4) | 0.33% | — | Pickplugins Related Post | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This issue affects Related Post: from n/a through 2.0.53. | |
| Modificada | Media (5.4) | 0.54% | — | Peachpay Related Products FOR Woocommerce | 22/11/2023 | 17/6/2026 | The Related Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'woo-related' shortcode in versions up to, and including, 3.3.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Analizada | Alta (8.8) | 0.94% | — | Yarpp YET Another Related Posts Plugin | 16/8/2023 | 17/6/2026 | The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks. | |
| Modificada | Media (5.4) | 0.51% | — | Yarpp YET Another Related Posts Plugin | 18/7/2023 | 17/6/2026 | The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (5.4) | 0.71% | — | Yarpp YET Another Related Posts Plugin | 13/2/2023 | 17/6/2026 | The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.54% | — | Webberzone Contextual Related Posts | 6/2/2023 | 17/6/2026 | The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.3) | 0.55% | — | Relatedcode Messenger | 19/10/2022 | 17/6/2026 | Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly. | |
| Modificada | Media (6.5) | 0.88% | — | Relatedcode Messenger | 19/10/2022 | 17/6/2026 | Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access sensitive data of any user of the application. This is possible because the application exposes user data to the public. | |
| Modificada | Media (5.4) | 1.2% | 💥 Exploit | Never5 Related Posts | 14/10/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3. | |
| Modificada | Media (4.8) | 0.69% | — | Never5 Related Posts | 19/7/2021 | 17/6/2026 | The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues. | |
| Modificada | Media (5.4) | 0.63% | — | Sovrn Wordpress Related Posts | 5/4/2021 | 17/6/2026 | The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the title field on the settings page. By exploiting that an attacker will be able to execute JavaScript code in the user's browser. | |
| Modificada | Media (5.4) | 0.63% | — | Never5 Related Posts | 5/4/2021 | 17/6/2026 | Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL. | |
| Modificada | Alta (7.5) | 11% | — | Apache TomcatDebian LinuxOpensuse LeapCanonical Ubuntu Linux+7 | 23/12/2019 | 17/6/2026 | When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been… | |
| Modificada | Media (5.9) | 1.4% | — | Oracle Micros Relate Customer Relationship Management Software | 16/10/2019 | 17/6/2026 | Vulnerability in the MICROS Relate CRM Software product of Oracle Retail Applications (component: Internal Operations). Supported versions that are affected are 7.1.0, 15.0.0, 16.0.0, 17.0.0, and 18.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.1) | 1.00% | — | Never5 Related Posts | 28/8/2019 | 17/6/2026 | The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |
| Modificada | Alta (8.8) | 1.0% | — | Meomundo Related Youtube Videos | 5/7/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Alta (8.2) | 1.1% | — | Oracle Micros Relate Customer Relationship Management Software | 23/4/2019 | 17/6/2026 | Vulnerability in the MICROS Relate CRM Software component of Oracle Retail Applications (subcomponent: Customer). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise MICROS Relate CRM Software. While the… | |
| Modificada | Media (6.4) | 1.1% | — | Oracle Micros Relate Customer Relationship Management Software | 18/7/2018 | 17/6/2026 | Vulnerability in the MICROS Relate CRM Software component of Oracle Retail Applications (subcomponent: Internal Operations). Supported versions that are affected are 10.8.x and 11.4.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MICROS Relate CRM Software.… | |
| Modificada | Media (5.9) | 17% | 💥 PoC | Apache TomcatRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerDebian Linux+6 | 28/2/2018 | 17/6/2026 | The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore,… |