Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.26% | — | Orchestrated Corona Virus (covid-19) Banner & Live Data | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Orchestrated Corona Virus (COVID-19) Banner & Live Data plugin <= 1.7.0.6 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Devowl Wordpress Real Cookie Banner | 16/1/2023 | 17/6/2026 | The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. | |
| Modificada | Alta (8.8) | 0.29% | — | Adrotate Banner Manager Project Adrotate Banner Manager | 30/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin <= 5.9 on WordPress. | |
| Modificada | Media (4.8) | 0.49% | — | Beautiful-cookie-banner Beautiful Cookie Consent Banner | 28/11/2022 | 17/6/2026 | The Beautiful Cookie Consent Banner WordPress plugin before 2.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.4) | 0.98% | — | Simple Banner Project Simple Banner | 6/9/2022 | 17/6/2026 | The Simple Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `pro_version_activation_code` parameter in versions up to, and including, 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, including those without… | |
| Modificada | Alta (8.8) | 0.68% | — | Banner Cycler Project Banner Cycler | 6/9/2022 | 17/6/2026 | The Banner Cycler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing nonce protection on the pabc_admin_slides_postback() function found in the ~/admin/admin.php file. This makes it possible for unauthenticated attackers to inject malicious web… | |
| Modificada | Media (4.8) | 0.54% | — | Simple Banner Project Simple Banner | 22/8/2022 | 17/6/2026 | The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (6.5) | 0.53% | — | Useful Banner Manager Project Useful Banner Manager | 13/6/2022 | 17/6/2026 | The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin by submitting a form. | |
| Modificada | Media (4.8) | 0.59% | — | Stillbreathing Bannerman | 30/5/2022 | 17/6/2026 | The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed (such as in multisite) | |
| Modificada | Media (6.5) | 0.53% | — | Devowl Wordpress Real Cookie Banner | 7/3/2022 | 17/6/2026 | The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (4.8) | 4.4% | — | Buffercode Random Banner | 18/1/2022 | 17/6/2026 | The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.4. This… | |
| Modificada | Alta (7.2) | 1.3% | — | Bannersky BSK PDF Manager | 29/11/2021 | 17/6/2026 | The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue | |
| Modificada | Media (4.8) | 0.62% | — | Bookingholdings Booking.com Banner Creator | 8/11/2021 | 17/6/2026 | The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.5) | 0.57% | — | Scroll Banner Project Scroll Banner | 18/10/2021 | 17/6/2026 | The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as well as XSS | |
| Modificada | Media (6.5) | 1.1% | — | WP Bannerize Project WP Bannerize | 6/10/2021 | 17/6/2026 | The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Classes/wpBannerizeAdmin.php file which allows attackers to exfiltrate sensitive information from vulnerable sites. This issue affects versions 2.0.0 - 4.0.2. | |
| Modificada | Media (5.4) | 0.62% | — | Gdprinfo Cookie Notice & Consent Banner FOR Gdpr & Ccpa Compliance | 6/9/2021 | 17/6/2026 | The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customization options. | |
| Modificada | Media (4.8) | 0.68% | — | Simple Banner Project Simple Banner | 23/8/2021 | 17/6/2026 | The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (7.2) | 1.7% | — | Wp-eventmanager Event Banner | 6/5/2021 | 17/6/2026 | The Event Banner WordPress plugin through 1.3 does not verify the uploaded image file, allowing admin accounts to upload arbitrary files, such as .exe, .php, or others executable, leading to RCE. Due to the lack of CSRF check, the issue can also be used via such vector to achieve the same result, or via a LFI as… | |
| Modificada | Alta (8.1) | 5.9% | 💥 PoC | Ellucian Banner Enterprise Identity ServicesEllucian Banner WEB Tailor | 14/5/2019 | 17/6/2026 | An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session… | |
| Modificada | Media (5.3) | 0.93% | — | Multidots Woocommerce Category Banner Management | 31/5/2018 | 17/6/2026 | class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data… | |
| Modificada | Media (6.1) | 1.3% | — | Ellucian Banner Student | 11/9/2017 | 17/6/2026 | Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter. | |
| Modificada | Crítica (9.8) | 2.3% | — | Ellucian Banner Student | 11/9/2017 | 17/6/2026 | Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset." | |
| Modificada | Media (5.3) | 2.0% | — | Ellucian Banner Student | 11/9/2017 | 17/6/2026 | Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests. | |
| Modificada | Media (6.1) | 1.2% | — | Ellucian Banner Student | 11/9/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |