Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.23% | — | Sivel Page Restrict | 28/2/2024 | 1/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5. | |
| Analizada | Media (5.3) | 0.50% | — | Sivel Page Restrict | 28/2/2024 | 1/9/2026 | The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts. | |
| Modificada | Media (5.3) | 0.48% | — | Pluginsandsnippets Simple Page Access Restriction | 8/2/2024 | 17/6/2026 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content. | |
| Modificada | Alta (7.5) | 0.61% | — | Cayenne Anonymous Restricted Content | 3/2/2024 | 17/6/2026 | The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is due to insufficient restrictions through the REST API on the posts/pages that protections are being place on. This makes it possible for unauthenticated attackers to access… | |
| Modificada | Media (4.8) | 0.40% | — | Benaceur-php Restrict Usernames Emails Characters | 29/1/2024 | 17/6/2026 | The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Alta (7.5) | 1.0% | 💥 PoC | Liquidweb Restrict Content | 23/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Vfbpro Restrict Categories | 14/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Matthew Muro Restrict Categories plugin <= 2.6.4 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Tickera Restrict | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Restrict plugin <= 2.2.4 versions. | |
| Modificada | Alta (7.7) | 0.68% | — | Zope Restrictedpython | 30/8/2023 | 17/6/2026 | RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling the format string to "read" all objects accessible through recursive attribute lookup and subscription from objects he can access. This can lead to critical information… | |
| Modificada | Media (6.1) | 0.49% | — | Liquidweb Restrict Content | 17/7/2023 | 17/6/2026 | The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Crítica (9.9) | 0.85% | — | Zope Restrictedpython | 11/7/2023 | 17/6/2026 | RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environment. RestrictedPython does not check access to stack frames and their attributes. Stack frames are accessible within at least generators and generator expressions, which… | |
| Modificada | Media (5.3) | 0.71% | — | 10up Restricted Site Access | 26/9/2022 | 17/6/2026 | The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations. | |
| Modificada | Media (4.8) | 0.60% | — | Minioragne Page Restriction | 25/4/2022 | 17/6/2026 | The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that will only affect administrator users. | |
| Modificada | Alta (8.8) | 1.7% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 13/9/2021 | 17/6/2026 | The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages. | |
| Modificada | Media (4.3) | 0.70% | — | Wp-upload-restriction Project Wp-upload-restriction | 7/7/2021 | 17/6/2026 | A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior. | |
| Modificada | Media (4.3) | 0.69% | — | Wp-upload-restriction Project Wp-upload-restriction | 7/7/2021 | 17/6/2026 | A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior. | |
| Modificada | Media (5.4) | 0.63% | — | Wp-upload-restriction Project Wp-upload-restriction | 7/7/2021 | 17/6/2026 | A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to inject arbitrary web scripts. This issue affects versions 2.2.3 and prior. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Content Restriction | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Content Restriction extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Baja (3.5) | 0.96% | — | Christian Johansson Restrict Node Page View | 30/11/2012 | 16/6/2026 | The Restrict node page view module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "view any node page" or "view any node {type} page" permission to access unpublished nodes via a direct request. |