Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.30% | — | Shapedplugin WP Tabs | 5/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC WP Tabs – Responsive Tabs Plugin for WordPress allows Stored XSS.This issue affects WP Tabs – Responsive Tabs Plugin for WordPress: from n/a through 2.2.0. | |
| Modificada | Crítica (9.8) | 0.64% | — | Mypresta Product Extra Tabs PRO | 17/10/2023 | 17/6/2026 | In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `extratabspro::searchcategory()`, `extratabspro::searchproduct()` and `extratabspro::searchmanufacturer().' | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution WP Responsive Tabs Horizontal Vertical AND Accordion Tabs | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs plugin <= 1.1.15 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Responsive Tabs FOR Wpbakery Page Builder Project Responsive Tabs FOR Wpbakery Page Builder | 19/6/2023 | 17/6/2026 | The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored… | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution WP Responsive Tabs | 9/6/2023 | 17/6/2026 | The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Alta (8.8) | 0.27% | — | WP Tabs Slides Project WP Tabs Slides | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Abdul Ibad WP Tabs Slides plugin <= 2.0.3 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Shapedplugin WP Tabs | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ShapedPlugin WP Tabs – Responsive Tabs Plugin for WordPress plugin <= 2.1.14 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Shapedplugin WP Tabs | 30/1/2023 | 17/6/2026 | The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (4.8) | 0.42% | — | Yikesinc Custom Product Tabs FOR Woocommerce | 18/11/2022 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Custom Product Tabs for WooCommerce plugin <= 1.7.9 on WordPress. | |
| Modificada | Media (5.4) | 0.51% | — | Tabs Project Tabs | 23/9/2022 | 17/6/2026 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress. | |
| Modificada | Alta (7.2) | 1.3% | — | Oxilab Responsive Tabs | 25/7/2022 | 17/6/2026 | Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress. | |
| Modificada | Media (5.3) | 1.5% | 💥 Exploit | Yikesinc Custom Product Tabs FOR Woocommerce | 21/7/2022 | 17/6/2026 | Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update. | |
| Modificada | Media (5.4) | 0.30% | — | Posttabs Project Posttabs | 13/6/2022 | 17/6/2026 | The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping | |
| Modificada | Media (4.8) | 0.59% | — | Wpshopmart Tabs Responsive | 23/5/2022 | 17/6/2026 | The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.8) | 33% | — | Skyoftech SO Listing Tabs | 17/5/2022 | 17/6/2026 | The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code execution because of deserialization of untrusted data. | |
| Modificada | Media (4.8) | 0.60% | — | Wpdarko Responsive Tabs | 11/4/2022 | 17/6/2026 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5 | |
| Modificada | Media (6.1) | 0.80% | — | Dtabs Project Dtabs | 28/3/2022 | 17/6/2026 | The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Alta (8.8) | 1.0% | — | Neo4j Graph Databse | 30/7/2021 | 17/6/2026 | A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execute commands with elevated privileges. | |
| Modificada | Media (4.8) | 0.53% | — | Quick Tabs Project Quick Tabs | 21/11/2019 | 24/9/2026 | Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal. | |
| Modificada | Crítica (9.8) | 3.2% | — | Tabslab Mailcarrier | 2/5/2019 | 17/6/2026 | A buffer overflow in the SMTP response service in MailCarrier 2.51 allows the attacker to execute arbitrary code remotely via a long HELP command, a related issue to CVE-2019-11395. | |
| Modificada | Crítica (9.8) | 15% | 💥 PoC | Tabslab Mailcarrier | 22/4/2019 | 17/6/2026 | A buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long string, as demonstrated by SMTP RCPT TO, POP3 USER, POP3 LIST, POP3 TOP, or POP3 RETR. | |
| Modificada | Crítica (9.8) | 10% | 💥 PoC | Designchemical Social Network Tabs | 21/3/2019 | 17/6/2026 | The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover. | |
| Modificada | Media (5.4) | 0.60% | — | Wpshopmart Tabs Responsive | 9/1/2018 | 17/6/2026 | The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php. | |
| Modificada | Baja (3.5) | 0.95% | — | OG Tabs Project OG Tabs | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the OG tabs module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes posted in an Organic Groups group. |