Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

103 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.82%—Awplife Slider Responsive Slideshow1/3/202417/6/2026
The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8 via deserialization of untrusted input to the awl_slider_responsive_shortcode function. This makes it possible for authenticated attackers, with…
ModificadaAlta (7.2)0.76%—Tribulant Slideshow Gallery20/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery LITE.This issue affects Slideshow Gallery LITE: from n/a through 1.7.6.
ModificadaMedia (5.4)0.45%—Gopiplus Image Horizontal Reel Scroll Slideshow19/12/202317/6/2026
The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ihrss-gallery' shortcode in versions up to, and including, 13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers…
ModificadaAlta (8.8)0.28%—Tribulant Slideshow Gallery12/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery LITE plugin <= 1.7.6 versions.
ModificadaMedia (6.5)0.79%—Gopiplus Jquery Accordion Slideshow31/10/202317/6/2026
The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
ModificadaMedia (6.5)0.79%—Gopiplus WP Image Slideshow31/10/202317/6/2026
The wp image slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with…
ModificadaMedia (6.5)0.79%—Gopiplus UP Down Image Slideshow Gallery31/10/202317/6/2026
The Up down image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
ModificadaMedia (6.5)0.79%—Gopiplus Superb Slideshow Gallery31/10/202317/6/2026
The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers…
ModificadaMedia (6.5)0.79%—Gopiplus Left Right Image Slideshow Gallery31/10/202317/6/2026
The Left right image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
ModificadaMedia (6.5)0.79%—Gopiplus Image Vertical Reel Scroll Slideshow31/10/202317/6/2026
The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
ModificadaMedia (6.5)1.5%—Gopiplus Image Horizontal Reel Scroll Slideshow31/10/202317/6/2026
The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
ModificadaMedia (4.8)0.32%—Gopiplus Image Vertical Reel Scroll Slideshow18/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Image vertical reel scroll slideshow plugin <= 9.0 versions.
ModificadaMedia (5.4)0.38%—2joomla 2J Slideshow2/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team Slideshow, Image Slider by 2J plugin <= 1.3.54 versions.
ModificadaMedia (6.1)0.35%—I13websolution WEB Solution Photo Gallery Slideshow & Masonry Tiled Gallery29/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Photo Gallery Slideshow & Masonry Tiled Gallery plugin <= 1.0.13 versions.
ModificadaMedia (6.1)0.43%—I13websolution Photo Gallery Slideshow & Masonry Tiled Gallery9/6/202317/6/2026
The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
ModificadaMedia (4.3)0.71%—2joomla 2J Slideshow7/6/202317/6/2026
The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'twoj_slideshow_setup' function called via the wp_ajax_twoj_slideshow_setup AJAX action in versions up to, and including, 1.3.31. This makes it possible for authenticated attackers (Subscriber, or above…
ModificadaMedia (5.4)0.37%—Portfolio Slideshow Project Portfolio Slideshow23/4/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in George Gecewicz Portfolio Slideshow plugin <= 1.13.0 versions.
ModificadaMedia (6.1)0.41%—Pixedelic Camera Slideshow20/3/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Manuel Masia | Pixedelic.Com Camera slideshow plugin <= 1.4.0.1 versions.
ModificadaMedia (5.4)0.38%—Slideshow SE Project Slideshow SE17/3/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.
ModificadaMedia (5.4)0.40%—Slideshow SE Project Slideshow SE16/3/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.
ModificadaMedia (4.8)0.59%—Ceikay Slideshow CK13/6/202217/6/2026
The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
ModificadaCrítica (9.8)11%—Dwbooster CP Image Store With Slideshow8/6/202217/6/2026
The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack
ModificadaMedia (4.8)0.59%—Slideshow Project Slideshow30/5/202217/6/2026
The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (5.4)0.53%—2joomla 2J Slideshow20/5/202217/6/2026
Authenticated (contributor or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team's Slideshow, Image Slider by 2J plugin <= 1.3.54 at WordPress.
ModificadaMedia (4.8)0.62%—Tribulant Slideshow Gallery23/11/202117/6/2026
The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed