Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.12% | — | Ayecode UserswpAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.48. | |
| Aplazada | Media (6.5) | 0.16% | — | Export ALL Posts Products Orders Refunds UsersAI | 2/12/2025 | 17/6/2026 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.19. This is due to missing or incorrect nonce validation on the `parseData` function. This makes it possible for unauthenticated attackers to export sensitive… | |
| Aplazada | Media (5.3) | 0.25% | — | Ayecode UserswpAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47. | |
| Aplazada | Alta (7.1) | 0.12% | — | Andriassundskard WpnamedusersAI | 6/11/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in andriassundskard wpNamedUsers wpnamedusers allows Stored XSS.This issue affects wpNamedUsers: from n/a through <= 0.5. | |
| Aplazada | Media (4.3) | 0.20% | — | Rustaurius Front END UsersAI | 22/10/2025 | 5/10/2026 | Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users.This issue affects Front End Users: from n/a through <= 3.2.33. | |
| Aplazada | Media (6.5) | 0.20% | — | Rustaurius Front END UsersAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Front End Users front-end-only-users allows Stored XSS.This issue affects Front End Users: from n/a through <= 3.2.35. | |
| Aplazada | Media (6.5) | 0.34% | — | Ayecode UserswpAI | 6/9/2025 | 17/6/2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘upload_file_remove’ function and 'htmlvar' parameter in all versions up to, and including, 1.2.44 due to insufficient escaping on the user… | |
| Aplazada | Media (6.4) | 0.24% | — | Ayecode UserswpAI | 28/8/2025 | 17/6/2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uwp_profile' and 'uwp_profile_header' shortcodes in all versions up to, and including, 1.2.42 due to insufficient input sanitization… | |
| Analizada | Media (4.3) | 0.26% | — | ARM 5TH GEN GPU Architecture Userspace DriverARM Bifrost GPU Userspace DriverARM Valhall GPU Userspace Driver | 4/8/2025 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to gain access to already freed memory.This… | |
| Analizada | Alta (8.8) | 0.86% | — | Gameusers Game Users Share Button | 28/6/2025 | 17/6/2026 | The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajaxDeleteTheme() function in all versions up to, and including, 1.3.0. This makes it possible for Subscriber-level attackers to add arbitrary file paths (such as… | |
| Aplazada | Alta (7.5) | 0.62% | — | Case-themes CtusersAI | 27/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Case-Themes CTUsers ctuser allows PHP Local File Inclusion.This issue affects CTUsers: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Rust UsersAI | 6/6/2025 | 17/6/2026 | A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list. | |
| Analizada | Media (6.1) | 0.16% | — | Hk1993 WP Online Users Stats | 6/6/2025 | 17/6/2026 | The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation within the hk_dataset_results() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged… | |
| Analizada | Media (4.9) | 0.37% | — | Hk1993 WP Online Users Stats | 6/6/2025 | 17/6/2026 | The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.19% | — | Anti Spam Spam Protection Block Spam Users Comments FormsAI | 6/6/2025 | 17/6/2026 | The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.7. This is due to missing or incorrect nonce validation in the 'ss_option_maint.php' and 'ss_user_filter_list' files. This makes it possible for… | |
| Analizada | Alta (7.8) | 0.16% | — | ARM 5TH GEN GPU Architecture Userspace DriverARM Bifrost GPU Userspace DriverARM Valhall GPU Userspace Driver | 2/6/2025 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL… | |
| Modificada | Crítica (9.8) | 0.29% | — | Etoilewebdesign Front END Users | 15/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Front End Users: from n/a through <= 3.2.35. | |
| Analizada | Alta (7.1) | 0.54% | 💥 Exploit | Etoilewebdesign Front END Users | 22/4/2025 | 17/6/2026 | The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.1) | 0.29% | — | Custom Users OrderAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiren Patel Custom Users Order custom-users-order allows Reflected XSS.This issue affects Custom Users Order: from n/a through <= 4.2. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Hk1993 WP Online Users StatsAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK WP Online Users Stats wp-online-users-stats allows Blind SQL Injection.This issue affects WP Online Users Stats: from n/a through <= 1.0.0. | |
| Analizada | Media (5.9) | 0.16% | — | ARM 5TH GEN GPU Architecture Userspace DriverARM Bifrost GPU Userspace DriverARM Valhall GPU Userspace Driver | 7/4/2025 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to make valid GPU processing operations, including via WebGL or… | |
| Modificada | Crítica (9.8) | 22% | 💥 PoC | Etoilewebdesign Front END Users | 2/4/2025 | 17/6/2026 | The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Modificada | Media (4.9) | 0.45% | — | Etoilewebdesign Front END Users | 2/4/2025 | 17/6/2026 | The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versions up to, and including, 3.2.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.77% | — | Webtoffee Export ALL Posts Products Orders Refunds UsersAI | 27/3/2025 | 17/6/2026 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in the 'returnMetaValueAsCustomerInput' function. This makes it possible for unauthenticated attackers to inject a PHP… | |
| Analizada | Media (4.9) | 0.73% | — | Webtoffee Import Export Wordpress Users | 22/3/2025 | 17/6/2026 | The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the… |