Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.62%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3.
AplazadaMedia (4.3)0.32%—Wpvibes Anywhere ElementorAI5/12/202417/6/2026
The AnyWhere Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.11 via the 'INSERT_ELEMENTOR' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and…
AnalizadaCrítica (9.8)35%💥 PoCVibethemes Wordpress Learning Management System9/11/202417/6/2026
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for…
ModificadaMedia (5.4)0.29%—Wpvibes Form Vibes5/9/202417/6/2026
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the fv_export_csv, reset_settings, save_settings, save_columns_settings, get_analytics_data, get_event_logs_data, delete_submissions, and…
ModificadaMedia (6.5)0.48%—Wpvibes Form Vibes12/7/202417/6/2026
The Form Vibes plugin for WordPress is vulnerable to SQL Injection via the ‘fv_export_data’ parameter in all versions up to, and including, 1.4.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
ModificadaCrítica (9.8)1.2%—Phpvibe9/7/20249/7/2026
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
ModificadaMedia (5.3)0.49%—Phpvibe18/6/202417/6/2026
A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp3.php of the component Media Upload Page. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit…
ModificadaMedia (5.1)0.36%—Phpvibe17/6/202417/6/2026
A vulnerability, which was classified as problematic, has been found in PHPVibe 11.0.46. This issue affects some unknown processing of the file functionalities.global.php of the component Global Options Page. The manipulation of the argument site-logo-text leads to cross site scripting. The attack may be initiated…
ModificadaAlta (7.2)0.98%—Wpvibes Form Vibes16/1/202417/6/2026
The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.
ModificadaAlta (8.8)0.61%—Wpvibes WP Mail LOG29/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WPVibes WP Mail Log.This issue affects WP Mail Log: from n/a through 1.1.2.
ModificadaAlta (8.8)11%—Wpvibes WP Mail LOG26/12/202317/6/2026
The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.
ModificadaAlta (8.8)1.1%—Wpvibes WP Mail LOG26/12/202317/6/2026
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.
ModificadaMedia (6.5)0.71%—Wpvibes WP Mail LOG26/12/202317/6/2026
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.
ModificadaAlta (8.8)0.72%—Wpvibes WP Mail LOG26/12/202317/6/2026
The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.
ModificadaAlta (7.6)0.50%—Wpvibes WP Mail LOG26/12/202317/6/2026
The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.
ModificadaAlta (7.2)0.73%—Wpvibes Redirect 404 Error Page TO Homepage OR Custom Page With Logs18/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPVibes Redirect 404 Error Page to Homepage or Custom Page with Logs allows SQL Injection.This issue affects Redirect 404 Error Page to Homepage or Custom Page with Logs: from n/a through 1.8.7.
ModificadaAlta (8.8)0.26%—Vibethemes Vslider17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 versions.
ModificadaMedia (6.1)0.46%—Wpvibes WP Mail LOG12/7/202317/6/2026
The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
AnalizadaAlta (8.8)0.30%—Vibethemes Wordpress Learning Management System11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions.
ModificadaMedia (5.3)0.62%—Wpvibes Anywhere Elementor30/5/202317/6/2026
The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.
ModificadaCrítica (9.8)1.6%—Vibethemes BP Social Connect19/5/202317/6/2026
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on…
AnalizadaMedia (4.8)0.37%—Vibethemes Vslider3/5/202317/6/2026
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 versions.
ModificadaAlta (8.8)0.26%—Wpvibes WP Mail LOG2/2/202317/6/2026
Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions.
ModificadaCrítica (9.8)2.7%—Softvibe Saraban18/1/202217/6/2026
SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution.
ModificadaAlta (7.5)1.7%—Softvibe Saraban18/1/202217/6/2026
SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication.
Orbitaley — Vulnerabilidades