Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.26% | — | Burhan Nasir Smart Auto Upload ImagesAI | 19/2/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Burhan Nasir Smart Auto Upload Images smart-auto-upload-images allows Server Side Request Forgery.This issue affects Smart Auto Upload Images: from n/a through <= 1.2.2. | |
| Aplazada | Media (5.3) | 0.33% | — | Alchemist Ajax UploadAI | 24/1/2026 | 17/6/2026 | The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capability check on the 'delete_file' function in all versions up to, and including, 1.1. This makes it possible for unauthenticated attackers to delete arbitrary WordPress media attachments. | |
| Aplazada | Media (5.3) | 0.22% | — | Imaginate-solutions File Uploads Addon FOR WoocommerceAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Imaginate Solutions File Uploads Addon for WooCommerce woo-addon-uploads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Uploads Addon for WooCommerce: from n/a through <= 1.7.3. | |
| Aplazada | Crítica (9.3) | 0.83% | — | UploadifyAI | 15/1/2026 | 16/6/2026 | Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file type validation. An unauthenticated remote attacker can upload arbitrary files to the affected WordPress site, which may allow remote code execution by uploading… | |
| Analizada | Media (6.1) | 0.24% | — | Wikimedia Mediawiki-extensions-uploadwizard | 8/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadWizard extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki - UploadWizard extension: 1.45, 1.44, 1.43, 1.39. | |
| Aplazada | Media (6.1) | 0.37% | — | Drag AND Drop Multiple File Upload Contact Form 7AI | 7/1/2026 | 30/9/2026 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all versions up to, and including, 1.3.9.2. This is due to the plugin not blocking .phar and .svg files. This makes it possible for unauthenticated attackers to upload… | |
| Aplazada | Media (4.3) | 0.22% | — | Fahadmahmood Easy Upload Files During CheckoutAI | 31/12/2025 | 28/9/2026 | Missing Authorization vulnerability in Fahad Mahmood Easy Upload Files During Checkout easy-upload-files-during-checkout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Upload Files During Checkout: from n/a through <= 3.0.0. | |
| Analizada | Baja (2.1) | 0.28% | — | Code-projects College Notes Uploading System | 29/12/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown function of the file /dashboard/userprofile.php. The manipulation of the argument image leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Modificada | Media (5.5) | 0.39% | — | Code-projects College Notes Uploading System | 29/12/2025 | 5/10/2026 | A weakness has been identified in code-projects College Notes Uploading System 1.0. This issue affects some unknown processing of the file /login.php. Executing a manipulation of the argument User can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and… | |
| Aplazada | Crítica (9.8) | 0.73% | — | File Uploader FOR WoocommerceAI | 20/12/2025 | 17/6/2026 | The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback function for the 'add-image-data' REST API endpoint in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to upload arbitrary… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Multi Uploader FOR Gravity FormsAI | 12/12/2025 | 17/6/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'plupload_ajax_delete_file' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the… | |
| Aplazada | Media (4.3) | 0.23% | — | Apprhyme URL Media UploaderAI | 12/12/2025 | 17/6/2026 | The URL Media Uploader plugin for WordPress is vulnerable to unauthorized safe file uploads due to a missing capability check on the url_media_uploader_url_upload_ajax_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (4.9) | 0.27% | — | Upload AMAI | 2/12/2025 | 25/9/2026 | The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options. | |
| Aplazada | Media (6.4) | 0.22% | — | Google Drive Upload AND Download LinkAI | 27/11/2025 | 17/6/2026 | The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter of the 'atachfilegoogle' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Alta (7) | 0.33% | — | Webform Multiple File Upload Project Webform Multiple File Upload | 26/11/2025 | 17/6/2026 | Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name renderer. An unauthenticated attacker can exploit this vulnerability by uploading a file with a malicious filename containing JavaScript code (e.g., "<img src=1 onerror=alert(document.domain)>") to a… | |
| Aplazada | Alta (7.2) | 0.23% | — | Checkout Files UploadAI | 18/11/2025 | 17/6/2026 | The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (8.8) | 0.64% | — | Enable SVG Webp AND ICO UploadAI | 18/11/2025 | 17/6/2026 | The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.1.3. This is due to insufficient file type validation detecting ICO files, allowing double extension files with the appropriate magic bytes to bypass sanitization while being… | |
| Aplazada | Media (6.4) | 0.22% | — | Enable SVG Webp AND ICO UploadAI | 18/11/2025 | 17/6/2026 | The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Aplazada | Alta (8.8) | 0.52% | — | Smart Auto Upload ImagesAI | 8/11/2025 | 17/6/2026 | The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the auto-image creation functionality in all versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload… | |
| Aplazada | Crítica (10) | 0.43% | — | Borisolhor Drop Uploader FOR CF7AI | 6/11/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploader Addon drop-uploader-for-contact-form-7-dragdrop-file-uploader-addon allows Upload a Web Shell to a Web Server.This issue affects Drop Uploader for CF7 - Drag&Drop File Uploader Addon: from n/a… | |
| Aplazada | Crítica (9.8) | 0.65% | — | Easy Upload Files During CheckoutAI | 4/11/2025 | 17/6/2026 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in the 'file_during_checkout' function in all versions up to, and including, 2.9.8. This makes it possible for unauthenticated attackers to upload arbitrary JavaScript files… | |
| Aplazada | Media (6.9) | 0.45% | — | Wikimedia Mediawiki Uploadwizard ExtensionAI | 18/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - UploadWizard Extension allows Stored XSS.This issue affects Mediawiki - UploadWizard Extension: from master before 1.39. | |
| Aplazada | Baja (2) | 0.25% | — | Lokibhardwaj Php-code-for-unlimited-file-uploadAI | 11/9/2025 | 17/6/2026 | A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument h causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made… | |
| Analizada | Baja (3.8) | 0.29% | — | Eliehanna Compress & Upload | 9/9/2025 | 10/7/2026 | The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup) | |
| Aplazada | Media (5.3) | 0.39% | — | VaadinAIVaadin-serverAIVaadin-upload-flowAI | 4/9/2025 | 14/9/2026 | When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 7.0.0 - 7.7.47 Vaadin 8.0.0 -… |