Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

78 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.39%—Conveythis Language Translate WidgetAI11/4/202417/6/2026
The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key’ parameter in all versions up to, and including, 223 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AnalizadaMedia (5.3)0.65%—Francisco Translate22/3/202417/6/2026
Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to version 3.0.0, an attacker controlling the second variable of the `translate` function is able to perform a cache poisoning attack. They can change the outcome of translation requests made by subsequent…
ModificadaCrítica (9.1)0.60%—Guelbetech Bravo Translate20/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Guelben Bravo Translate.This issue affects Bravo Translate: from n/a through 1.2.
ModificadaBaja (3.7)0.49%—Cjvnjde Google Translate API Browser24/11/202317/6/2026
google-translate-api-browser is an npm package which interfaces with the google translate web api. A Server-Side Request Forgery (SSRF) Vulnerability is present in applications utilizing the `google-translate-api-browser` package and exposing the `translateOptions` to the end user. An attacker can set a malicious…
ModificadaMedia (4.8)0.47%—Translate Wordpress With Gtranslate25/9/202317/6/2026
The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). This…
ModificadaMedia (4.3)0.38%—Qtranslate Slug Project Qtranslate Slug12/7/202317/6/2026
The Qtranslate Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.18. This is due to missing or incorrect nonce validation on the save_postdata() function. This makes it possible for unauthenticated attackers to save post data via a forged request granted they…
ModificadaMedia (4.8)0.37%—Simple Slug Translate Project Simple Slug Translate16/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ko Takagi Simple Slug Translate plugin <= 2.7.2 versions.
ModificadaMedia (6.1)0.34%—Wpglobus Translate Options7/4/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPGlobus WPGlobus Translate Options plugin <= 2.1.0 versions.
ModificadaMedia (6.1)0.56%—Qtranslate Slug Project Qtranslate Slug6/3/202317/6/2026
A vulnerability was found in Qtranslate Slug Plugin up to 1.1.16 on WordPress. It has been classified as problematic. Affected is the function add_slug_meta_box of the file includes/class-qtranslate-slug.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to…
ModificadaAlta (8.8)5.2%💥 ExploitCozmoslabs Translatepress19/9/202217/6/2026
The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected.
ModificadaCrítica (9.8)2.1%—Catly Translate Project Catly Translate24/6/202217/6/2026
The Catly-Translate package in PyPI v0.0.3 to v0.0.5 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaMedia (5.4)3.8%💥 ExploitLoco Translate Project Loco Translate18/4/202217/6/2026
The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript…
ModificadaAlta (8.8)0.61%—Translate Wordpress With Gtranslate28/3/202217/6/2026
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin…
ModificadaMedia (4.7)0.75%—Translate Wordpress With Gtranslate7/2/202217/6/2026
The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT…
ModificadaMedia (6.5)0.94%—Loco Translate Project Loco Translate8/11/202117/6/2026
The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.
ModificadaMedia (4.8)0.68%—Gtranslate Google Language Translator8/11/202117/6/2026
The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (4.8)5.4%💥 ExploitCozmoslabs Translatepress27/9/202117/6/2026
The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site…
ModificadaCrítica (9.8)2.3%—Onlyoffice Google Translate10/9/202117/6/2026
The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.
ModificadaMedia (6.1)1.6%💥 ExploitGtranslate30/7/202117/6/2026
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected…
ModificadaMedia (6.1)4.5%💥 ExploitTranslate Wordpress With Gtranslate20/4/202017/6/2026
The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
ModificadaMedia (6.1)1.0%—Translatehouse Pootle28/10/201916/6/2026
pootle 2.0.5 has XSS via 'match_names' parameter
ModificadaMedia (6.5)0.87%—Qtranslate X Project Qtranslate X26/9/201917/6/2026
The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter.
ModificadaAlta (8.8)0.67%—Mythemeshop MY WP Translate20/8/201917/6/2026
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
ModificadaMedia (6.1)0.91%—Mythemeshop MY WP Translate20/8/201917/6/2026
The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
ModificadaMedia (6.1)0.95%—Gtranslate Google Language Translator13/8/201917/6/2026
The google-language-translator plugin before 5.0.06 for WordPress has XSS.
Orbitaley — Vulnerabilidades