Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.45% | — | Joomdonation Membership PROAI | 21/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets. | |
| Aplazada | Media (6.1) | 0.36% | — | Fuint Member Marketing SystemAI | 20/7/2026 | 21/7/2026 | Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageController.java file | |
| Aplazada | Media (5.3) | 0.30% | — | User Registration MembershipAI | 17/7/2026 | 17/7/2026 | The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to delete recently-registered, payment-pending user accounts. | |
| Aplazada | Alta (8.1) | 0.38% | 💥 PoC | User Registration AND MembershipAI | 17/7/2026 | 17/7/2026 | The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published… | |
| Aplazada | Alta (8.6) | 0.53% | — | Wpswings Membership FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0. | |
| Aplazada | Crítica (9.1) | 0.45% | — | User Registration MembershipAI | 13/7/2026 | 13/7/2026 | The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated attackers to forge a payment-approved event and activate a paid membership subscription without completing a real payment. | |
| Aplazada | Alta (8.1) | 0.35% | — | User Registration Membership User Registration AND MembershipAI | 13/7/2026 | 13/7/2026 | The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify from a caller-supplied identifier instead of the current user, allowing any authenticated user such as a subscriber to change another user's WordPress… | |
| Aplazada | Media (5.3) | 0.47% | — | Samsung MembersAI | 11/7/2026 | 14/7/2026 | The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest. This makes it possible for unauthenticated attackers to extract determine the existence and exact count… | |
| Aplazada | Media (5.3) | 0.72% | — | ArmemberAI | 10/7/2026 | 14/7/2026 | The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain files (e.g., CSS) to directories outside the 'wp-content/uploads/armember' directory. | |
| Aplazada | Alta (7.5) | 0.51% | — | Ultimatemember Ultimate MemberAI | 10/7/2026 | 10/7/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Media (4.3) | 0.34% | — | Profilegrid Memberships AND User Profiles FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid()… | |
| Aplazada | Media (4.9) | 0.44% | — | Hashicorp MemberlistAI | 8/7/2026 | 9/7/2026 | HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist… | |
| Aplazada | Alta (8.1) | 0.40% | — | Wclovers Wcfm MembershipAI | 8/7/2026 | 8/7/2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it… | |
| Aplazada | Alta (8.8) | 0.51% | — | Simple-membership-plugin Simple MembershipAI | 6/7/2026 | 6/7/2026 | The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in… | |
| Aplazada | Alta (8) | 0.41% | — | Ultimatemember Ultimate MemberAI | 6/7/2026 | 6/7/2026 | The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript that executes when any user, including an administrator,… | |
| Aplazada | Media (6.4) | 0.42% | — | Ultimatemember Ultimate MemberAI | 3/7/2026 | 6/7/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'about_me' parameter in all versions up to, and including, 2.11.4 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Alta (7.2) | 0.27% | — | Paid Member SubscriptionsAI | 2/7/2026 | 2/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. | |
| Aplazada | Alta (8.8) | 0.52% | — | Reputeinfosystems Armember PremiumAI | 2/7/2026 | 3/8/2026 | Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This issue affects ARMember Premium: from n/a before 7.6. | |
| Aplazada | Media (6.5) | 0.27% | — | User Registration MembershipAI | 2/7/2026 | 2/7/2026 | The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before activating a paid membership subscription, allowing unauthenticated users (after self-registering an account through the open registration flow) to obtain an active subscription on any paid plan without paying… | |
| Aplazada | Media (4.4) | 0.34% | — | Team Members Multi Language Supported Team PluginAI | 30/6/2026 | 30/6/2026 | The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Alta (8.1) | 0.38% | — | Paid Membership PluginAI | 27/6/2026 | 29/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active… | |
| Aplazada | Alta (8.8) | 0.20% | — | Paidmembershipspro Paid Memberships PROAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | User Registration AND MembershipAI | 26/6/2026 | 26/6/2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Silabs Emberznet SDKAI | 25/6/2026 | 25/6/2026 | Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage. | |
| Analizada | Alta (7.1) | 0.44% | — | Silabs Emberznet | 25/6/2026 | 25/6/2026 | In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. |