Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)1.1%—Gorilla SchemaAI1/7/202417/6/2026
gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations, taking advantage of the sparse slice functionality. Any use of `schema.Decoder.Decode()`…
AplazadaMedia (6.5)0.59%—WP Schema PRO Schema PROAI19/6/202417/6/2026
Missing Authorization vulnerability in WP SCHEMA PRO Schema Pro.This issue affects Schema Pro: from n/a through 2.7.8.
AplazadaMedia (4.3)0.25%—Schemaapp Schema APP Structured DataAI14/6/202417/6/2026
The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the MarkUpdate function. This makes it possible for unauthenticated attackers to update and delete post metadata via a…
ModificadaMedia (4.3)0.34%—Schemaapp Schema APP Structured Data24/5/202417/6/2026
The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the MarkupUpdate function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber access or higher, to update or delete…
AplazadaAlta (8.1)0.80%—Json-schema-ref-parserAI20/5/202417/6/2026
A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, `dereference() functions.
AplazadaMedia (6.4)0.33%—Schema AND Structured Data FOR WP AND AMPAI23/4/202417/6/2026
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "How To" and "FAQ" Blocks in all versions up to, and including, 1.29 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AnalizadaMedia (4.3)0.45%—Brainstormforce Schema25/3/202417/6/2026
The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode
ModificadaMedia (5.4)0.37%—Magazine3 Schema & Structured Data FOR WP & AMP29/2/202417/6/2026
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom schema in all versions up to, and including, 1.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in…
ModificadaMedia (4.3)0.43%—Magazine3 Schema & Structured Data FOR WP & AMP29/2/202417/6/2026
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saswp_reviews_form_render' function in all versions up to, and including, 1.26. This makes it possible for authenticated attackers, with contributor access and…
ModificadaMedia (5.4)0.33%—Structured-data-for-wp Download Schema & Structured Data FOR WP & AMP1/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.23.
ModificadaMedia (5.4)0.34%—Magazine3 Schema & Structured Data FOR WP & AMP31/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.25.
ModificadaMedia (4.3)0.43%—Radiustheme Review Schema31/1/202417/6/2026
The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtrs_review_edit() function in all versions up to, and including, 2.1.14. This makes it possible for authenticated attackers, with…
ModificadaAlta (8.8)0.30%—Brainstormforce Schema30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro: from n/a through 2.7.7.
ModificadaMedia (4.3)0.39%—Websitescanner Remove Schema1/7/202317/6/2026
The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted…
AnalizadaAlta (8.8)0.26%—Brainstormforce Schema26/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions.
ModificadaMedia (5.4)0.47%—Terakoya Markup (json-ld) Structured IN Schema.org21/2/202317/6/2026
The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.52%—Schema Project Schema12/7/202217/6/2026
The schema (aka Embedding schema.org vocabulary) extension before 1.13.1 and 2.x before 2.5.1 for TYPO3 allows XSS.
ModificadaMedia (5.4)0.60%—Fivestarplugins Five Star Business Profile AND Schema21/2/202217/6/2026
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of…
ModificadaCrítica (9.8)3.8%—Json-schema Project Json-schemaDebian Linux13/11/202117/6/2026
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
ModificadaAlta (7.5)2.1%—Schema-inspector Project Schema-inspectorNetapp E-series Performance AnalyzerNetapp Oncommand Insight19/3/202117/6/2026
Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example…
ModificadaAlta (8)2.1%—Databaseschemareader Project Dbschemareader4/11/202017/6/2026
DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.
ModificadaAlta (7.5)1.5%—Simpl-schema Project Simpl-schema7/10/202017/6/2026
This affects the package simpl-schema before 1.10.2.
ModificadaCrítica (9.8)1.4%—Schema-inspector Project Schema-inspector22/1/202017/6/2026
In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector.
AnalizadaMedia (6.1)0.90%—Brainstormforce Schema21/8/201917/6/2026
The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page.
ModificadaAlta (8.8)0.87%—Tibco Messaging - Apache Kafka Distribution - Schema Repository6/11/201817/6/2026
The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition contains a vulnerability which may allow an attacker to perform…