Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
196 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.28% | — | TestimonialAI | 10/9/2025 | 17/6/2026 | The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions up to, and including, 2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,… | |
| Aplazada | Crítica (9.1) | 0.40% | — | ValtimoAICamundaAI | 28/8/2025 | 17/6/2026 | Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to before 13.1.2.RELEASE, any admin that can create or modify and execute process-definitions could gain access to sensitive data or resources. This includes but is not limited to: running executables on… | |
| Aplazada | Crítica (10) | 0.48% | — | Imran EMU TC TestimonialsAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC Testimonials allows Stored XSS. This issue affects TC Testimonials: from n/a through 1.1.1. | |
| Aplazada | Crítica (9.4) | 0.41% | — | Joomla NO Boss TestimonialsAI | 28/7/2025 | 17/6/2026 | A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered. | |
| Aplazada | Media (6.4) | 0.23% | — | Testimonial Post TypeAI | 18/7/2025 | 17/6/2026 | The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (6.4) | 0.25% | — | Strong TestimonialsAI | 15/7/2025 | 17/6/2026 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fields in all versions up to, and including, 3.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.26% | — | Cmoreira Testimonials ShowcaseAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Testimonials Showcase testimonials-showcase allows Reflected XSS.This issue affects Testimonials Showcase: from n/a through <= 1.9.16. | |
| Modificada | Media (6.1) | 0.26% | 💥 PoC | Jetimob Imobiliaria | 10/6/2025 | 5/7/2026 | Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section via the field "Profisso" (professor). | |
| Modificada | Media (6.1) | 0.26% | 💥 PoC | Jetimob Imobiliaria | 10/6/2025 | 5/7/2026 | Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript. | |
| Modificada | Media (6.1) | 0.26% | 💥 PoC | Jetimob Imobiliaria | 10/6/2025 | 5/7/2026 | Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) inside the filter Save option in the "Busca" (search) function. | |
| Modificada | Media (6.1) | 0.26% | 💥 PoC | Jetimob Imobiliaria | 10/6/2025 | 5/7/2026 | Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field "Observaces" (observances) in the "Pessoas" (persons) section when creating or editing either a legal or a natural person. | |
| Aplazada | Media (4.3) | 0.28% | — | Cmoreira Testimonials ShowcaseAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in cmoreira Testimonials Showcase testimonials-showcase allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonials Showcase: from n/a through <= 1.9.16. | |
| Aplazada | Alta (8.3) | 0.33% | — | ValtimoAI | 30/5/2025 | 17/6/2026 | Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12.0.0.RELEASE to 12.12.0.RELEASE, all objects for which an object-management configuration exists can be listed, viewed, edited, created or deleted by unauthorised users. If object-urls are exposed… | |
| Aplazada | Media (5.3) | 0.36% | — | Gsplugins GS Testimonial SliderAI | 7/5/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in GS Plugins GS Testimonial Slider gs-testimonial allows Code Injection.This issue affects GS Testimonial Slider: from n/a through <= 3.2.9. | |
| Aplazada | Media (4.3) | 0.29% | — | Gsplugins GS Testimonial SliderAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in GS Plugins GS Testimonial Slider gs-testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Testimonial Slider: from n/a through <= 3.3.0. | |
| Analizada | Crítica (9.8) | 0.78% | — | Orban Optimod 5950 Firmware | 18/4/2025 | 17/6/2026 | Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges. | |
| Aplazada | Media (6.5) | 0.27% | — | Shapedplugin Real TestimonialsAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Stored XSS.This issue affects Real Testimonials: from n/a through <= 3.1.6. | |
| Aplazada | Alta (8.1) | 0.93% | — | Radiustheme Testimonial Slider AND Showcase PROAI | 11/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slider And Showcase Pro testimonial-slider-showcase-pro allows PHP Local File Inclusion.This issue affects Testimonial Slider And Showcase Pro: from n/a through <= 2.3.15. | |
| Aplazada | Alta (8.8) | 0.49% | — | Pickplugins Testimonial SliderAI | 3/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider testimonial allows Object Injection.This issue affects Testimonial Slider: from n/a through <= 2.0.13. | |
| Aplazada | Media (4.3) | 0.25% | — | Repuso Social-testimonials-and-reviews-widgetAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso social-testimonials-and-reviews-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social proof testimonials and reviews by Repuso: from n/a through <= 5.21. | |
| Aplazada | Media (5.4) | 0.15% | — | Elfsight Testimonials SliderAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Cross Site Request Forgery.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.9) | 0.26% | — | Elfsight Testimonials SliderAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Stored XSS.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.4) | 0.32% | — | Elfsight Testimonials SliderAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.37% | — | Travis Ballard Tb-testimonialsAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Travis Ballard TBTestimonials tb-testimonials allows Reflected XSS.This issue affects TBTestimonials: from n/a through <= 1.7.3. | |
| Aplazada | Media (5.3) | 0.38% | — | Wpchill Strong TestimonialsAI | 25/2/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Strong Testimonials: from n/a through <= 3.2.3. |