Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.33% | — | Tipsandtricks-hq WP Emember | 13/7/2024 | 17/6/2026 | The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Media (5.4) | 0.40% | — | Tipsandtricks-hq WP Emember | 13/7/2024 | 17/6/2026 | The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Media (5.3) | 0.31% | — | Tips AND Tricks HQ Stripe PaymentsAI | 4/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79. | |
| Analizada | Alta (8.3) | 0.44% | — | Tipsandtricks-hq WP Emember | 4/6/2024 | 17/6/2026 | The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. | |
| Aplazada | Alta (7.5) | 0.52% | — | Tips AND Tricks HQ WP Express CheckoutAI | 17/5/2024 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7. | |
| Aplazada | Media (6.4) | 0.44% | — | Tipsandtricks-hq WP Video LightboxAI | 2/5/2024 | 17/6/2026 | The WP Video Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 1.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Alta (7.5) | 0.47% | — | Tips AND Tricks HQ Easy Accept PaymentsAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Tips and Tricks HQ Easy Accept Payments.This issue affects Easy Accept Payments: from n/a through 4.9.10. | |
| Aplazada | Media (4.3) | 0.21% | — | Tipsandtricks-hq ALL IN ONE WP Security & FirewallAI | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall.This issue affects All In One WP Security & Firewall: from n/a through 5.2.6. | |
| Aplazada | Media (6.5) | 0.32% | — | Tipsandtricks-hq Compact WP Audio PlayerAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Compact WP Audio Player allows Stored XSS.This issue affects Compact WP Audio Player: from n/a through 1.9.9. | |
| Modificada | Media (4.8) | 0.30% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 27/1/2024 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic redirect URL setting in all versions up to and including 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Modificada | Media (5.4) | 0.22% | — | Patrickposner Qyrr | 16/1/2024 | 17/6/2026 | The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site Scripting attacks. Furthermore, the data_uri_to_meta AJAX action, available to all authenticated users, only had a CSRF check in place, with the nonce available to users with… | |
| Modificada | Alta (8.8) | 0.82% | — | Patrickrobrecht Posts AND Users Stats | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Patrick Robrecht Posts and Users Stats.This issue affects Posts and Users Stats: from n/a through 1.1.3. | |
| Modificada | Crítica (9.8) | 0.72% | — | Tipsandtricks-hq Simple Photo Gallery | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Peter Petreski Simple Photo Gallery simple-photo-gallery allows SQL Injection.This issue affects Simple Photo Gallery: from n/a through v1.8.1. | |
| Modificada | Media (4.8) | 0.37% | — | Tipsandtricks-hq Category Specific RSS Feed Subscription | 12/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.2 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Tipsandtricks-hq Category Specific RSS Feed Subscription | 3/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions. | |
| Modificada | Media (4.8) | 0.35% | — | Tipsandtricks-hq WP Express Checkout | 17/3/2023 | 17/6/2026 | The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access to inject… | |
| Modificada | Media (5.3) | 0.55% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 16/3/2023 | 17/6/2026 | The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it… | |
| Modificada | Media (5.4) | 0.54% | — | Tipsandtricks-hq Easy Accept Payments FOR Paypal | 13/2/2023 | 17/6/2026 | The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.53% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 23/1/2023 | 17/6/2026 | The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege… | |
| Modificada | Media (5.4) | 0.47% | — | Tipsandtricks-hq Compact WP Audio Player | 23/1/2023 | 17/6/2026 | The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Media (5.4) | 0.47% | — | Tipsandtricks-hq WP Video Lightbox | 16/1/2023 | 17/6/2026 | The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (6.5) | 0.46% | — | Tipsandtricks-hq WP Affiliate Platform | 29/11/2022 | 17/6/2026 | The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce validation on various functions including the affiliates_menu method. This makes it possible for unauthenticated attackers to delete affiliate… | |
| Modificada | Media (4.8) | 0.55% | — | Tipsandtricks-hq WP Affiliate Platform | 29/11/2022 | 17/6/2026 | The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Modificada | Media (6.1) | 0.62% | — | Tipsandtricks-hq WP Affiliate Platform | 29/11/2022 | 17/6/2026 | The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Media (4.8) | 0.56% | — | Tipsandtricks-hq Donations VIA Paypal | 28/11/2022 | 17/6/2026 | The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |