Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.25% | — | Joaopaulocdev Calculation Fields | 26/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation Fields allows Cross-Site Scripting (XSS).This issue affects Calculation Fields: from 0.0.0 before 1.0.4. | |
| Aplazada | Media (4.3) | 0.34% | — | Smart Custom FieldsAI | 23/3/2026 | 17/6/2026 | The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to read private… | |
| Aplazada | Media (4.4) | 0.19% | — | Mandatory FieldAI | 21/3/2026 | 17/6/2026 | The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Media (4.3) | 0.19% | — | ADD Custom Fields TO MediaAI | 19/3/2026 | 17/6/2026 | The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.3. This is due to missing nonce validation on the field deletion functionality in the admin display template. The plugin properly validates a nonce for the 'add field' operation… | |
| Analizada | Crítica (9.1) | 0.30% | 💥 PoC | Teclib-edition Fields | 16/3/2026 | 17/6/2026 | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3. | |
| Aplazada | Media (6.4) | 0.33% | — | Calculated Fields FormAI | 13/3/2026 | 17/6/2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in all versions up to, and including, 5.4.5.0. This is due to insufficient capability checks on the form settings save handler and insufficient input sanitization of the `fcontent` field in `fhtml` field… | |
| Aplazada | Media (5.3) | 0.29% | — | Wombat Advanced Product Fields FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Wombat Plugins Advanced Product Fields (Product Addons) for WooCommerce advanced-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Product Fields (Product Addons) for WooCommerce: from n/a through <=… | |
| Aplazada | Alta (7.2) | 0.42% | — | Themehelper Checkout Field EditorAI | 11/3/2026 | 17/6/2026 | The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and checkboxgroup field values submitted through the WooCommerce Block Checkout Store API in all versions up to, and including, 2.1.7. This is due to the… | |
| Aplazada | Alta (7.1) | 0.19% | — | Hugh Mungus Visitor Maps Extended Referer FieldAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Visitor Maps Extended Referer Field visitor-maps-extended-referer-field allows Reflected XSS.This issue affects Visitor Maps Extended Referer Field: from n/a through <= 1.2.6. | |
| Aplazada | Alta (7.7) | 0.47% | — | Vanquish User Extra FieldsAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue affects User Extra Fields: from n/a through <= 17.0. | |
| Aplazada | Alta (8.6) | 0.54% | — | Vanquish User Extra FieldsAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue affects User Extra Fields: from n/a through <= 17.0. | |
| Aplazada | Alta (7.1) | 0.18% | — | Vanquish User Extra FieldsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Reflected XSS.This issue affects User Extra Fields: from n/a through <= 16.8. | |
| Aplazada | Media (6.5) | 0.26% | — | Codepeople Calculated Fields FormAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculated Fields Form: from n/a through <= 5.4.4.1. | |
| Aplazada | Media (6.4) | 0.30% | — | Advanced Custom Fields Font Awesome FieldAI | 19/2/2026 | 17/6/2026 | The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible forauthenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (5.3) | 0.42% | — | Checkout Field ManagerAI | 19/2/2026 | 17/6/2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.8.5. This is due to the plugin not properly verifying that a user is authorized to delete an attachment combined with flawed guest order ownership validation.… | |
| Aplazada | Media (5.3) | 0.34% | — | Checkout Field ManagerAI | 19/2/2026 | 17/6/2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versions up to, and including, 7.8.1. This is due to the plugin not properly verifying that a user is authorized to perform file upload actions via the… | |
| Aplazada | Media (4.3) | 0.28% | — | Navz ACF Photo Gallery FieldAI | 19/2/2026 | 17/6/2026 | The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "acf_photo_gallery_edit_save" function in all versions up to, and including, 3.0. This makes it possible for authenticated attackers, with subscriber level access and above, to… | |
| Aplazada | Crítica (9.8) | 1.5% | — | Acfextended Advanced Custom Fields ExtendedAI | 20/1/2026 | 17/6/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated attackers to supply the… | |
| Aplazada | Media (6.4) | 0.18% | — | Table Field AddonAI | 6/1/2026 | 17/6/2026 | The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table Cell Content in all versions up to, and including, 1.3.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and… | |
| Aplazada | Alta (8.8) | 0.72% | — | Buddypress Xprofile Custom Field TypesAI | 6/1/2026 | 7/10/2026 | The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_field' function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Crítica (9.8) | 0.37% | — | AS Password Field IN Default Registration FormAI | 6/1/2026 | 7/10/2026 | The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.20% | — | Wpgogo Custom Field TemplateAI | 29/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template custom-field-template allows Stored XSS.This issue affects Custom Field Template: from n/a through <= 2.7.7. | |
| Aplazada | Alta (7.2) | 0.39% | — | Silverplugins217 Custom-fields-account-registration-for-woocommerceAI | 18/12/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in silverplugins217 Custom Fields Account Registration For Woocommerce custom-fields-account-registration-for-woocommerce allows Privilege Escalation.This issue affects Custom Fields Account Registration For Woocommerce: from n/a through <= 1.2. | |
| Aplazada | Media (4.3) | 0.15% | — | Advanced Product FieldsAI | 9/12/2025 | 17/6/2026 | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.17. This is due to missing or incorrect nonce validation on the 'maybe_duplicate' function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.3) | 0.22% | — | Vanquish User Extra FieldsAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Extra Fields: from n/a through <= 16.8. |