Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.49% | — | History LOG BY Click5AI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in click5 History Log by click5 history-log-by-click5 allows SQL Injection.This issue affects History Log by click5: from n/a through <= 1.0.13. | |
| Aplazada | Media (6.5) | 0.20% | — | Ninjateam Click TO Chat WP Support ALL IN ONE Floating WidgetAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.4. | |
| Aplazada | Alta (7.5) | 0.47% | — | ClickhouseAI | 20/3/2025 | 17/6/2026 | When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamically load a library from a specified path and execute it in an isolated process. Combined with the ClickHouse table engine functionality that permits file uploads to… | |
| Analizada | Alta (7.1) | 0.27% | — | S-A WP Click Info | 13/3/2025 | 17/6/2026 | The WP Click Info WordPress plugin through 2.7.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Alta (7.1) | 0.37% | — | Dactum Clickbank StorefrontAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dactum ClickBank Storefront mycbgenie-clickbank-storefront allows Reflected XSS.This issue affects ClickBank Storefront: from n/a through <= 1.7. | |
| Modificada | Alta (8.8) | 0.18% | — | Flowdee Clickwhale | 25/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ClickWhale ClickWhale clickwhale allows Cross Site Request Forgery.This issue affects ClickWhale: from n/a through <= 2.4.3. | |
| Modificada | Media (5.9) | 1.6% | 💥 Exploit | 1clickmigration 1 Click Migration | 18/2/2025 | 17/6/2026 | The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the class-ocm-backup.php. This makes it possible for unauthenticated attackers to extract sensitive data including usernames and their… | |
| Modificada | Media (4.3) | 0.21% | — | 1clickmigration 1 Click Migration | 18/2/2025 | 17/6/2026 | The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the cancel_actions() function. This makes it possible for unauthenticated attackers… | |
| Analizada | Alta (8.1) | 0.46% | — | Mvpthemes Click MAG | 12/2/2025 | 17/6/2026 | The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to, and including, 3.6.0. This makes it possible for… | |
| Analizada | Media (5.4) | 0.25% | — | Flowdee Clickwhale | 29/1/2025 | 17/6/2026 | The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Media (6.1) | 0.35% | — | Flowdee Clickwhale | 11/1/2025 | 17/6/2026 | The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.1. This makes it… | |
| Aplazada | Media (6.1) | 0.35% | — | Whatsapp Click TO ChatAI | 9/1/2025 | 17/6/2026 | The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts_code' parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Alta (8.5) | 0.38% | — | Flowdee Clickwhale | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWhale clickwhale allows Blind SQL Injection.This issue affects ClickWhale: from n/a through <= 2.4.1. | |
| Aplazada | Media (5.3) | 0.40% | — | ClickdesignsAI | 7/1/2025 | 17/6/2026 | The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions in all versions up to, and including, 1.8.0. This makes it possible for unauthenticated attackers to modify or remove the… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpswings ONE Click Upsell Funnel FOR WoocommerceAI | 21/12/2024 | 17/6/2026 | The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Upsell & Cross Sell Offers that Boost Sales & Increase Profits with Sales Funnel Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wps_wocuf_pro_yes shortcode in… | |
| Aplazada | Media (5.4) | 0.49% | — | Clicktotweet Click TO TweetAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in ClickToTweet.com Click To Tweet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Click To Tweet: from n/a through 2.0.14. | |
| Aplazada | Alta (7.6) | 0.45% | — | Barco Clickshare Cx-30AIBarco Clickshare Cx-20AIBarco Clickshare C-5AIBarco Clickshare C-10AI+2 | 10/12/2024 | 17/6/2026 | An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command execution as root. | |
| Aplazada | Media (6.1) | 0.15% | — | Clickbank StorefrontAI | 6/12/2024 | 17/6/2026 | The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing or incorrect nonce validation via the cs_menu page. This makes it possible for unauthenticated attackers to update settings and inject malicious… | |
| Aplazada | Alta (8.8) | 0.41% | — | Clickstudios PasswordstateAI | 29/11/2024 | 17/6/2026 | In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen. | |
| Aplazada | Media (6.5) | 0.39% | — | Kiran Patil Location Click MAPAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiran Patil Location Click Map location-click-map allows Stored XSS.This issue affects Location Click Map: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.39% | — | Magnetic Creative Inline Click TO TweetAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnetic Creative Inline Click To Tweet inline-click-to-tweet allows DOM-Based XSS.This issue affects Inline Click To Tweet: from n/a through <= 1.0.0. | |
| Analizada | Media (4.3) | 0.38% | — | Zixn BUY ONE Click Woocommerce | 13/11/2024 | 17/6/2026 | The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buy_one_click_import_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Analizada | Media (4.3) | 0.35% | — | Zixn BUY ONE Click Woocommerce | 13/11/2024 | 17/6/2026 | The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the removeorder AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete Buy… | |
| Aplazada | Media (4.3) | 0.40% | — | BUY ONE ClickAI | 13/11/2024 | 17/6/2026 | The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the buy_one_click_export_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Modificada | Crítica (9.8) | 1.1% | 💥 PoC | Swoopnow 1-click Login\ | 28/10/2024 | 17/6/2026 | Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5. |