Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.19% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.41. | |
| Aplazada | Alta (7.6) | 0.21% | — | Kod8 Software Technologies Trade Kod8 Individual AND SME WebsiteAI | 3/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kod8 Software Technologies Trade Ltd. Co. Kod8 Individual and SME Website allows Reflected XSS. This issue affects Kod8 Individual and SME Website: through 03022026. NOTE: The vendor was contacted early about… | |
| Analizada | Alta (8.8) | 0.56% | 💥 PoC | Eclipse Theia Website | 30/1/2026 | 17/6/2026 | In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access to repository secrets… | |
| Analizada | Alta (8.7) | 0.98% | — | Websitebaker | 16/1/2026 | 17/6/2026 | WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve remote code execution on the server. | |
| Aplazada | Media (4.3) | 0.24% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.40. | |
| Modificada | Media (5.1) | 0.24% | — | Websitebaker | 19/12/2025 | 17/6/2026 | WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating web pages. Attackers can craft malicious payloads in page titles that execute arbitrary JavaScript when the page is viewed by other users. | |
| Analizada | Media (5.1) | 0.24% | — | Websitebaker | 16/12/2025 | 17/6/2026 | WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files with script tags that execute when the file is viewed, enabling persistent cross-site scripting attacks. | |
| Analizada | Alta (7) | 1.0% | — | Websitebaker | 16/12/2025 | 17/6/2026 | WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory. | |
| Aplazada | Media (5.3) | 0.90% | 💥 Exploit | Feedback Modal FOR WebsiteAI | 5/12/2025 | 17/6/2026 | The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_export' function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to export all feedback data in CSV or JSON format via the… | |
| Aplazada | Baja (2.1) | 0.32% | — | Jairiidriss RestaurantwebsiteAI | 1/12/2025 | 3/9/2026 | A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654. Impacted is an unknown function of the component Make a Reservation. This manipulation of the argument selected_date causes cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.32% | — | Winston-dsouza Ecommerce-websiteAI | 30/11/2025 | 3/9/2026 | A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the argument Error can lead to cross site… | |
| Analizada | Media (5.5) | 0.39% | — | Torrahclef Company Website CMS | 23/11/2025 | 17/6/2026 | A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.39% | — | Torrahclef Company Website CMS | 23/11/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/reset-password.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Media (6.5) | 0.24% | — | Hackerwhale Restaurant Website Restoran | 19/11/2025 | 17/6/2026 | Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page. | |
| Aplazada | Media (6.1) | 0.21% | — | Artibot Free Chat BOT FOR WebsitesAI | 18/11/2025 | 17/6/2026 | The ArtiBot Free Chat Bot for WebSites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (6.5) | 0.24% | — | Kashipara Ecommerce Website | 17/11/2025 | 17/6/2026 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php. | |
| Analizada | Media (6.5) | 0.24% | — | Kashipara Ecommerce Website | 17/11/2025 | 17/6/2026 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php. | |
| Analizada | Media (6.5) | 0.24% | — | Kashipara Ecommerce Website | 17/11/2025 | 17/6/2026 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php. | |
| Aplazada | Baja (2) | 0.28% | — | Iqbolshoh Php-business-websiteAI | 17/11/2025 | 17/6/2026 | A security vulnerability has been detected in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This affects an unknown part of the file /admin/about.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed publicly… | |
| Analizada | Media (5.3) | 0.35% | — | Toastwebsites Find Unused Images | 11/11/2025 | 17/6/2026 | The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() functiosn in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to delete all of a site's… | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian E-commerce Website | 28/10/2025 | 17/6/2026 | A vulnerability was determined in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/supplier_update.php. This manipulation of the argument supp_name/supp_address causes cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian E-commerce Website | 27/10/2025 | 17/6/2026 | A vulnerability was found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument prod_name/prod_desc/prod_cost results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could… | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian E-commerce Website | 27/10/2025 | 17/6/2026 | A vulnerability has been found in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/supplier_add.php. The manipulation of the argument supp_name/supp_address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Baja (2) | 0.31% | — | Ashymuzuro Full-ecommece-websiteAIMuzuro Ecommerce SystemAI | 27/10/2025 | 17/6/2026 | A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an unknown part of the file /admin/index.php?add_product of the component Add Product Page. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Baja (2) | 0.25% | — | Iqbolshoh Php-business-websiteAI | 27/10/2025 | 1/10/2026 | A flaw has been found in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This vulnerability affects unknown code of the file admin/contact.php. This manipulation of the argument twitter causes cross site scripting. The attack may be initiated remotely. The exploit has been published and… |