Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

127 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.38%—Heateor Social Comments4/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin for Vkontakte Comments and Disqus Comments plugin <= 1.6.1 versions.
ModificadaMedia (5.4)0.36%—Heateor Fancy Comments30/3/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Team Heateor Fancy Comments WordPress plugin <= 1.2.10 versions.
ModificadaMedia (5.4)0.64%—Markjaquith Subscribe TO Comments5/3/202316/6/2026
A vulnerability, which was classified as problematic, was found in Subscribe to Comments Plugin up to 2.0.7 on WordPress. This affects an unknown part of the file subscribe-to-comments.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.8 is…
ModificadaMedia (6.1)0.90%💥 ExploitAppjetty Show ALL Comments16/1/202317/6/2026
The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.
ModificadaMedia (4.8)0.56%—ADD Comments Project ADD Comments5/12/202217/6/2026
The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (6.1)0.55%—Prestashop Productcomments2/9/202217/6/2026
This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an administrator's cookie. The issue is fixed in version 5.0.2.
ModificadaMedia (6.5)0.66%—Stop Spam Comments Project Stop Spam Comments29/8/202217/6/2026
The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment section, allowing threat authors to easily collect the value and add it to the request.
ModificadaMedia (4.8)0.61%—Najeebmedia Wordpress Comments Fields8/8/202217/6/2026
The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (6.1)2.9%—Turn OFF ALL Comments Project Turn OFF ALL Comments23/5/202217/6/2026
The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (5.4)0.39%—Wpkube Subscribe TO Comments Reloaded29/4/202217/6/2026
Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key, reset all options, change notifications…
ModificadaMedia (4.8)0.60%—Wpdevart Social Comments25/4/202217/6/2026
The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (4.8)0.60%—Good-bad-comments Project Good-bad-comments18/4/202217/6/2026
The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (6.5)0.62%—Delete ALL Comments Easily Project Delete ALL Comments Easily1/11/202117/6/2026
The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.
ModificadaMedia (6.1)0.90%—Sw-guide Edit Comments XT10/9/202117/6/2026
The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.
ModificadaAlta (7.5)0.89%—Onyaktech Comments PRO Project Onyaktech Comments PRO7/9/202117/6/2026
An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the installer, decompile it, and discover a hardcoded IV used to encrypt the username and userid in the comment POST request. Additionally, the attacker can decrypt the encrypted encryption key (sent as a…
ModificadaMedia (5.4)0.62%—Onyaktech Comments PRO Project Onyaktech Comments PRO7/9/202117/6/2026
An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment.
ModificadaCrítica (9.8)1.9%—Edit Comments Project Edit Comments23/8/202117/6/2026
The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue
ModificadaMedia (5.3)0.98%—Wphappycoders Comments Like Dislike21/6/202117/6/2026
The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin appears to have some Restriction modes,…
ModificadaMedia (5.3)2.1%💥 ExploitThrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+1612/4/202117/6/2026
The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive…
ModificadaAlta (8.2)12%💥 ExploitPrestashop Productcomments3/12/202017/6/2026
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
ModificadaMedia (6.1)0.89%—Prestashop Product Comments16/11/202017/6/2026
In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0
ModificadaAlta (8.1)0.61%—Nodebb Blog Comments26/8/202017/6/2026
In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.
ModificadaMedia (5.4)0.54%—Verbb Comments5/6/202017/6/2026
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.
ModificadaMedia (5.4)0.54%—Verbb Comments5/6/202017/6/2026
An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name.
Orbitaley — Vulnerabilidades