Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
1229 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.21% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 18/8/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.6 versions. | |
| Modificada | Media (6.1) | 0.56% | — | Margox Braft-editor | 11/8/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in margox braft-editor version 2.3.8, allows remote attackers to execute arbitrary code via the embed media feature. | |
| Modificada | Media (6.1) | 0.52% | — | Kindsoft Kindeditor | 11/8/2023 | 17/6/2026 | La vulnerabilidad de Cross-Site Scripting (XSS) en el parámetro content1 en demo.jsp en kindsoft kindeditor versión 4.1.12, permite a los atacantes ejecutar código arbitrario. | |
| Modificada | Media (6.1) | 0.68% | — | JBT Live (github-flavored) Markdown Editor | 11/8/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Rendering Engine in jbt Markdown Editor thru commit 2252418c27dffbb35147acd8ed324822b8919477, allows remote attackers to execute arbirary code via crafted payload or opening malicious .md file. | |
| Modificada | Media (6.1) | 0.57% | — | Ckeditor-wordcount-plugin Project Ckeditor-wordcount-plugin | 21/7/2023 | 17/6/2026 | ckeditor-wordcount-plugin es un complemento WordCount de código abierto para CKEditor. Se ha descubierto que el complemento `ckeditor-wordcount-plugin` para CKEditor4 es susceptible a Cross-Site Scripting al cambiar al modo de código fuente. Este problema se solucionó en la versión 1.17.12 del complemento… | |
| Modificada | Media (6.7) | 0.18% | — | BD Alaris Guardrails Editor | 13/7/2023 | 17/6/2026 | A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs. | |
| Modificada | Media (5.4) | 0.90% | — | Xwiki Ckeditor IntegrationXwiki | 30/6/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' space. This makes it possible to perform a variety of harmful actions, such as removing technical documents, leading to loss of service and editing the… | |
| Modificada | Alta (7.2) | 0.85% | — | Wpwox Responsive CSS Editor | 27/6/2023 | 17/6/2026 | The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admin. | |
| Modificada | Media (5.4) | 0.44% | — | Editorial Calendar Project Editorial Calendar | 27/6/2023 | 17/6/2026 | The Editorial Calendar WordPress plugin before 3.8.3 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting vulnerability targeting higher privileged users. | |
| Modificada | Alta (8.8) | 0.26% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Manager Professional | 22/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions. | |
| Modificada | Crítica (9.8) | 1.4% | 💥 PoC | Ckeditor | 13/6/2023 | 9/7/2026 | A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server. | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Media (4.3) | 0.79% | — | Webdevocean WP Quick Frontend Editor | 7/6/2023 | 17/6/2026 | El plugin WP Quick FrontEnd para WordPress es vulnerable a la inyección de contenido de páginas en versiones hasta la v5.5 inclusive. Esto se debe a la falta de comprobaciones en la funcionalidad de edición de páginas del plugin. Esto hace posible que atacantes poco autenticados, como los suscriptores, editen/creen… | |
| Modificada | Media (5.4) | 0.49% | — | Webdevocean WP Quick Frontend Editor | 7/6/2023 | 17/6/2026 | El plugin WP Quick FrontEnd Editor para WordPress es vulnerable a Cross-Site Scripting Almacenado en versiones hasta la v5.5 inclusive, debido a una insuficiente sanitización de entrada y escape de salida. Esto hace posible que atacantes autenticados, con permisos mínimos como suscriptores, inyecten scripts web… | |
| Modificada | Media (4.3) | 0.66% | — | Pluginmirror WP Quick Frontend Editor | 7/6/2023 | 17/6/2026 | The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Setting Changs in versions up to, and including, 5.5. This is due to lacking both a security nonce and a capabilities check. This makes it possible for low-authenticated attackers to change plugin settings even when they do not have the capabilities to… | |
| Modificada | Media (6.1) | 0.74% | — | Webdevocean WP Quick Frontend Editor | 7/6/2023 | 17/6/2026 | The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on the 'save_content_front' function that uses print_r on the user-supplied $_REQUEST values . This makes it possible for… | |
| Modificada | Alta (8.8) | 0.30% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions. | |
| Modificada | Alta (7.8) | 0.16% | — | Foxit PDF EditorFoxit PDF Reader | 19/5/2023 | 17/6/2026 | Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory because unprivileged users have access to an… | |
| Modificada | Media (4.8) | 0.35% | — | Waspthemes Visual CSS Style Editor | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WaspThemes Visual CSS Style Editor plugin <= 7.5.8 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Woocommerce Custom Checkout Fields Editor With Drag & Drop Project Woocommerce Custom Checkout Fields Editor With Drag & Drop | 9/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Umair Saleem Woocommerce Custom Checkout Fields Editor With Drag & Drop plugin <= 0.1 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Ipandao Editor.md | 8/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values. | |
| Modificada | Media (6.1) | 0.43% | — | Ipandao Editor.md | 1/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text. | |
| Modificada | Crítica (9.8) | 0.72% | — | Editorial Calendar Project Editorial Calendar | 8/4/2023 | 16/6/2026 | A vulnerability was found in Editorial Calendar Plugin up to 2.6 on WordPress. It has been declared as critical. Affected by this vulnerability is the function edcal_filter_where of the file edcal.php. The manipulation of the argument edcal_startDate/edcal_endDate leads to sql injection. The attack can be launched… | |
| Modificada | Media (6.1) | 0.66% | — | Ipandao Editor.md | 4/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter. | |
| Modificada | Media (6.1) | 0.66% | — | Ipandao Editor.md | 4/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe>src parameter. |