Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
200 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.20% | — | Oren Yomtov Mass Custom Fields ManagerAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Oren Yomtov Mass Custom Fields Manager mass-custom-fields-manager allows Reflected XSS.This issue affects Mass Custom Fields Manager: from n/a through <= 1.5. | |
| Analizada | Alta (7.3) | 0.35% | — | Allow ALL File Extensions FOR File Fields Project Allow ALL File Extensions FOR File Fields | 9/1/2025 | 17/6/2026 | Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*. | |
| Aplazada | Alta (7.1) | 0.31% | — | Pjfc SyncfieldsAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pjfc SyncFields syncfields allows Reflected XSS.This issue affects SyncFields: from n/a through <= 2.1. | |
| Aplazada | Media (6.5) | 0.26% | — | Takashi Kitajima Smart Custom FieldsAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Kitajima Smart Custom Fields smart-custom-fields allows Stored XSS.This issue affects Smart Custom Fields: from n/a through <= 5.0.0. | |
| Aplazada | Media (4.3) | 0.30% | — | Justcoded Just Custom FieldsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in JustCoded / Alex Prokopenko Just Custom Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Just Custom Fields: from n/a through 3.3.2. | |
| Aplazada | Alta (7.7) | 0.49% | — | Teclib-edition FieldsAI | 26/12/2024 | 17/6/2026 | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13. | |
| Analizada | Media (5.3) | 0.58% | — | Codepeople Calculated Fields Form | 17/12/2024 | 17/6/2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width parameters for CAPTCHA images. This makes it possible for unauthenticated attackers to send multiple requests with large values, resulting in… | |
| Aplazada | Media (4.3) | 0.23% | — | Wpengine INC Advanced Custom Fields PROAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPENGINE, INC. Advanced Custom Fields PRO.This issue affects Advanced Custom Fields PRO: from n/a before 6.3.2. | |
| Aplazada | Crítica (9.8) | 0.49% | — | MSA Fieldserver GatewayAI | 10/12/2024 | 17/6/2026 | An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe shared secret that is static in all affected firmware versions. | |
| Aplazada | Crítica (9.8) | 0.46% | — | MSA Fieldserver GatewayAI | 10/12/2024 | 17/6/2026 | An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow them to authenticate with an internal user… | |
| Aplazada | Media (4.3) | 0.34% | — | Jules Colle Conditional Fields FOR Contact Form 7AI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jules Colle Conditional Fields for Contact Form 7 cf7-conditional-fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conditional Fields for Contact Form 7: from n/a through <= 2.4.1. | |
| Aplazada | Media (4.3) | 0.43% | — | Josevega Display Custom Fields IN THE Frontend Post AND User Profile FieldsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jose Vega Display custom fields in the frontend – Post and User Profile Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display custom fields in the frontend – Post and User Profile Fields: from n/a through 1.2.0. | |
| Aplazada | Media (4.3) | 0.18% | — | MSA Fieldserver GatewayAI | 29/11/2024 | 17/6/2026 | MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking. | |
| Analizada | Media (6.5) | 0.76% | — | Tychesoftwares Product Input Fields FOR Woocommerce | 26/11/2024 | 17/6/2026 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (6.9) | 0.47% | — | Django CMS Association Django CMS Attributes FieldsAI | 20/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django CMS Attributes Fields allows Stored XSS. This issue affects django CMS Attributes Fields: before 4.0. | |
| Analizada | Media (6.6) | 0.43% | — | Advancedcustomfields Advanced Custom Fields | 15/11/2024 | 17/6/2026 | The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin… | |
| Analizada | Crítica (9.8) | 1.4% | — | Vanquish User Extra Fields | 13/11/2024 | 17/6/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 16.6. This makes it possible for unauthenticated attackers to delete arbitrary files on the server,… | |
| Analizada | Alta (8.8) | 0.82% | — | Vanquish User Extra Fields | 13/11/2024 | 17/6/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields() function in all versions up to, and including, 16.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to add custom fields… | |
| Aplazada | Crítica (9.8) | 0.85% | — | Wordpress User Extra FieldsAI | 9/11/2024 | 17/6/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() function in all versions up to, and including, 16.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected… | |
| Aplazada | Media (5.4) | 0.30% | — | Wpengine INC Advanced Custom Fields PROAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1. | |
| Aplazada | Media (4.3) | 0.32% | — | Wpengine Advanced Custom Fields PROAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1. | |
| Aplazada | Media (5.9) | 0.26% | — | Jules Colle CF7 Conditional FieldsAI | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jules Colle Conditional Fields for Contact Form 7 cf7-conditional-fields allows Stored XSS.This issue affects Conditional Fields for Contact Form 7: from n/a through <= 2.4.15. | |
| Analizada | Media (5.4) | 0.33% | — | Felipeelia Contact Form 7 Repeatable Fields | 24/10/2024 | 17/6/2026 | The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's field_group shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (4.8) | 0.28% | — | Aftabhusain Category AND Taxonomy Meta Fields | 22/10/2024 | 17/6/2026 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image meta field value in the 'wpaft_add_meta_textinput' function in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Media (4.8) | 0.28% | — | Aftabhusain Category AND Taxonomy Meta Fields | 22/10/2024 | 17/6/2026 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_meta_name' parameter in the 'wpaft_option_page' function in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… |