Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

721 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Adenion Blog2socialAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.
AplazadaMedia (4.3)0.21%—Inisev Social Media AND Share IconsAI17/6/20261/10/2026
: Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6.
AplazadaAlta (7.1)0.25%—Social Slider FeedAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.
AplazadaAlta (8.8)0.35%—Moosocial Store PluginAI25/5/202623/7/2026
mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product…
AplazadaMedia (5.5)0.52%—Klik SocialmediawebsiteAI25/5/202623/7/2026
A vulnerability was identified in KLiK SocialMediaWebsite 1.0. This issue affects some unknown processing of the component HTTP POST Request Parameter Handler. Such manipulation leads to injection. The attack can be launched remotely. The exploit is publicly available and might be used.
AplazadaMedia (5.5)0.50%—Klik SocialmediawebsiteAI25/5/202623/7/2026
A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File Handler. This manipulation causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaBaja (2.1)0.42%—Klik SocialmediawebsiteAI25/5/202623/7/2026
A vulnerability was found in KLiK SocialMediaWebsite 1.0. This affects an unknown part of the component HTTP GET Request Parameter Handler. The manipulation results in injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
AplazadaAlta (8.8)0.24%—Appyap Technology AND Information INC Yaay Social Media APPAI14/5/20267/10/2026
Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Yaay Social Media App: from 3.8.0 through 24102025.
AplazadaMedia (5.4)0.51%—Adenion Blog2socialAI13/5/202617/6/2026
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 8.9.0. This is due to a missing ownership verification in the B2S_Post_Tools::deleteUserPublishPost() and B2S_Post_Tools::deleteUserSchedPost() functions, neither…
AplazadaMedia (6.4)0.33%—Advanced Social Media IconsAI12/5/202617/6/2026
The Advanced Social Media Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `social` shortcode in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaMedia (5.1)0.24%—Accesspress Social IconsAI10/5/202625/7/2026
AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon title' field. Attackers can store XSS payloads like image tags with onerror event handlers that execute when the plugin page…
AplazadaMedia (5.4)0.32%—MY Social FeedsAI2/5/202617/6/2026
The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 1.0.4 via the 'ttp_get_accounts' AJAX action. This is due to the complete absence of authorization checks (no capability verification) and nonce verification in the…
AplazadaMedia (6.5)0.83%💥 ExploitTrustindex Widgets FOR Social Photo FeedAI2/5/20267/10/2026
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and…
AplazadaMedia (6.4)0.35%—Social Post EmbedAI28/4/202617/6/2026
The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in all versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on the user-supplied URL. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.8)0.32%—Directorist Social LoginAI27/4/202617/6/2026
Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4.
AplazadaMedia (6.9)0.40%—Klik SocialmediawebsiteAI25/4/202617/6/2026
A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Executing a manipulation of the argument c_id can lead to sql injection. It is possible to launch the attack remotely.
AplazadaAlta (8.2)0.66%—Ossn Open Source Social NetworkAI24/4/202617/6/2026
Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a specially crafted image with extreme pixel dimensions (e.g., $10000 \times 10000$ pixels). While the compressed file size on disk may be…
ModificadaMedia (6.3)0.46%—Socialengine23/4/202617/6/2026
SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is not sanitized before being used to construct outbound HTTP requests. Authenticated remote attackers can supply arbitrary…
ModificadaCrítica (9.3)1.0%—Socialengine23/4/202617/6/2026
SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. An unauthenticated remote attacker can exploit this vulnerability to read…
AplazadaMedia (6.4)0.19%—Wpsocialrocket Social RocketAI23/4/202617/6/2026
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access…
AplazadaMedia (6.4)0.33%—Easy Social Photos GalleryAI22/4/202617/6/2026
The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class' shortcode attribute of the 'my-instagram-feed' shortcode in all versions up to, and including, 3.1.2. This is due to insufficient input sanitization and output escaping on user supplied attributes.…
AplazadaMedia (4.3)0.49%—Adenion Blog2socialAI8/4/202624/7/2026
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through user-controlled key in all versions up to, and including, 8.8.3. This is due to the plugin's AJAX handlers failing to validate that the user-supplied 'b2s_id' parameter belongs to the current user…
AplazadaAlta (7.5)0.16%—Analytify Simple Social Media Share ButtonsAI7/4/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects Simple Social Media Share Buttons: from n/a through 6.2.0.
AplazadaAlta (7.2)0.39%—Widgets FOR Social Photo FeedAI4/4/202624/7/2026
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaBaja (2.1)0.32%—Code-projects Social Networking SiteAI27/3/202617/6/2026
A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of the component Endpoint. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and…
Orbitaley — Vulnerabilidades