Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.39% | — | Conveythis Language Translate WidgetAI | 11/4/2024 | 17/6/2026 | The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key’ parameter in all versions up to, and including, 223 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Media (5.3) | 0.65% | — | Francisco Translate | 22/3/2024 | 17/6/2026 | Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to version 3.0.0, an attacker controlling the second variable of the `translate` function is able to perform a cache poisoning attack. They can change the outcome of translation requests made by subsequent… | |
| Modificada | Crítica (9.1) | 0.60% | — | Guelbetech Bravo Translate | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Guelben Bravo Translate.This issue affects Bravo Translate: from n/a through 1.2. | |
| Modificada | Baja (3.7) | 0.49% | — | Cjvnjde Google Translate API Browser | 24/11/2023 | 17/6/2026 | google-translate-api-browser is an npm package which interfaces with the google translate web api. A Server-Side Request Forgery (SSRF) Vulnerability is present in applications utilizing the `google-translate-api-browser` package and exposing the `translateOptions` to the end user. An attacker can set a malicious… | |
| Modificada | Media (4.8) | 0.47% | — | Translate Wordpress With Gtranslate | 25/9/2023 | 17/6/2026 | The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). This… | |
| Modificada | Media (4.3) | 0.38% | — | Qtranslate Slug Project Qtranslate Slug | 12/7/2023 | 17/6/2026 | The Qtranslate Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.18. This is due to missing or incorrect nonce validation on the save_postdata() function. This makes it possible for unauthenticated attackers to save post data via a forged request granted they… | |
| Modificada | Media (4.8) | 0.37% | — | Simple Slug Translate Project Simple Slug Translate | 16/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ko Takagi Simple Slug Translate plugin <= 2.7.2 versions. | |
| Modificada | Media (6.1) | 0.34% | — | Wpglobus Translate Options | 7/4/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPGlobus WPGlobus Translate Options plugin <= 2.1.0 versions. | |
| Modificada | Media (6.1) | 0.56% | — | Qtranslate Slug Project Qtranslate Slug | 6/3/2023 | 17/6/2026 | A vulnerability was found in Qtranslate Slug Plugin up to 1.1.16 on WordPress. It has been classified as problematic. Affected is the function add_slug_meta_box of the file includes/class-qtranslate-slug.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to… | |
| Modificada | Alta (8.8) | 5.2% | 💥 Exploit | Cozmoslabs Translatepress | 19/9/2022 | 17/6/2026 | The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected. | |
| Modificada | Crítica (9.8) | 2.1% | — | Catly Translate Project Catly Translate | 24/6/2022 | 17/6/2026 | The Catly-Translate package in PyPI v0.0.3 to v0.0.5 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Media (5.4) | 3.8% | 💥 Exploit | Loco Translate Project Loco Translate | 18/4/2022 | 17/6/2026 | The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript… | |
| Modificada | Alta (8.8) | 0.61% | — | Translate Wordpress With Gtranslate | 28/3/2022 | 17/6/2026 | The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin… | |
| Modificada | Media (4.7) | 0.75% | — | Translate Wordpress With Gtranslate | 7/2/2022 | 17/6/2026 | The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT… | |
| Modificada | Media (6.5) | 0.94% | — | Loco Translate Project Loco Translate | 8/11/2021 | 17/6/2026 | The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations. | |
| Modificada | Media (4.8) | 0.68% | — | Gtranslate Google Language Translator | 8/11/2021 | 17/6/2026 | The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.8) | 5.4% | 💥 Exploit | Cozmoslabs Translatepress | 27/9/2021 | 17/6/2026 | The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site… | |
| Modificada | Crítica (9.8) | 2.3% | — | Onlyoffice Google Translate | 10/9/2021 | 17/6/2026 | The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields. | |
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Gtranslate | 30/7/2021 | 17/6/2026 | In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected… | |
| Modificada | Media (6.1) | 4.5% | 💥 Exploit | Translate Wordpress With Gtranslate | 20/4/2020 | 17/6/2026 | The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option. | |
| Modificada | Media (6.1) | 1.0% | — | Translatehouse Pootle | 28/10/2019 | 16/6/2026 | pootle 2.0.5 has XSS via 'match_names' parameter | |
| Modificada | Media (6.5) | 0.87% | — | Qtranslate X Project Qtranslate X | 26/9/2019 | 17/6/2026 | The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter. | |
| Modificada | Alta (8.8) | 0.67% | — | Mythemeshop MY WP Translate | 20/8/2019 | 17/6/2026 | The my-wp-translate plugin before 1.0.4 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 0.91% | — | Mythemeshop MY WP Translate | 20/8/2019 | 17/6/2026 | The my-wp-translate plugin before 1.0.4 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.95% | — | Gtranslate Google Language Translator | 13/8/2019 | 17/6/2026 | The google-language-translator plugin before 5.0.06 for WordPress has XSS. |