Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

128 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.9)0.33%—Tipsandtricks-hq WP Emember13/7/202417/6/2026
The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AnalizadaMedia (5.4)0.40%—Tipsandtricks-hq WP Emember13/7/202417/6/2026
The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaMedia (5.3)0.31%—Tips AND Tricks HQ Stripe PaymentsAI4/6/202417/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79.
AnalizadaAlta (8.3)0.44%—Tipsandtricks-hq WP Emember4/6/202417/6/2026
The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
AplazadaAlta (7.5)0.52%—Tips AND Tricks HQ WP Express CheckoutAI17/5/202417/6/2026
Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.
AplazadaMedia (6.4)0.44%—Tipsandtricks-hq WP Video LightboxAI2/5/202417/6/2026
The WP Video Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 1.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaAlta (7.5)0.47%—Tips AND Tricks HQ Easy Accept PaymentsAI29/4/202417/6/2026
Missing Authorization vulnerability in Tips and Tricks HQ Easy Accept Payments.This issue affects Easy Accept Payments: from n/a through 4.9.10.
AplazadaMedia (4.3)0.21%—Tipsandtricks-hq ALL IN ONE WP Security & FirewallAI29/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall.This issue affects All In One WP Security & Firewall: from n/a through 5.2.6.
AplazadaMedia (6.5)0.32%—Tipsandtricks-hq Compact WP Audio PlayerAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Compact WP Audio Player allows Stored XSS.This issue affects Compact WP Audio Player: from n/a through 1.9.9.
ModificadaMedia (4.8)0.30%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart27/1/202417/6/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic redirect URL setting in all versions up to and including 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
ModificadaMedia (5.4)0.22%—Patrickposner Qyrr16/1/202417/6/2026
The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site Scripting attacks. Furthermore, the data_uri_to_meta AJAX action, available to all authenticated users, only had a CSRF check in place, with the nonce available to users with…
ModificadaAlta (8.8)0.82%—Patrickrobrecht Posts AND Users Stats7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in Patrick Robrecht Posts and Users Stats.This issue affects Posts and Users Stats: from n/a through 1.1.3.
ModificadaCrítica (9.8)0.72%—Tipsandtricks-hq Simple Photo Gallery3/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Peter Petreski Simple Photo Gallery simple-photo-gallery allows SQL Injection.This issue affects Simple Photo Gallery: from n/a through v1.8.1.
ModificadaMedia (4.8)0.37%—Tipsandtricks-hq Category Specific RSS Feed Subscription12/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.2 versions.
ModificadaAlta (8.8)0.27%—Tipsandtricks-hq Category Specific RSS Feed Subscription3/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions.
ModificadaMedia (4.8)0.35%—Tipsandtricks-hq WP Express Checkout17/3/202317/6/2026
The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access to inject…
ModificadaMedia (5.3)0.55%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart16/3/202317/6/2026
The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it…
ModificadaMedia (5.4)0.54%—Tipsandtricks-hq Easy Accept Payments FOR Paypal13/2/202317/6/2026
The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.53%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart23/1/202317/6/2026
The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege…
ModificadaMedia (5.4)0.47%—Tipsandtricks-hq Compact WP Audio Player23/1/202317/6/2026
The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such…
ModificadaMedia (5.4)0.47%—Tipsandtricks-hq WP Video Lightbox16/1/202317/6/2026
The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as…
ModificadaMedia (6.5)0.46%—Tipsandtricks-hq WP Affiliate Platform29/11/202217/6/2026
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce validation on various functions including the affiliates_menu method. This makes it possible for unauthenticated attackers to delete affiliate…
ModificadaMedia (4.8)0.55%—Tipsandtricks-hq WP Affiliate Platform29/11/202217/6/2026
The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to…
ModificadaMedia (6.1)0.62%—Tipsandtricks-hq WP Affiliate Platform29/11/202217/6/2026
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaMedia (4.8)0.56%—Tipsandtricks-hq Donations VIA Paypal28/11/202217/6/2026
The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Orbitaley — Vulnerabilidades