Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.73% | — | Tipsandtricks-hq WP Video Lightbox | 25/7/2022 | 17/6/2026 | The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |
| Modificada | Media (6.1) | 0.80% | — | I13websolution Team Circle Image Slider With Lightbox | 14/3/2022 | 17/6/2026 | The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Media (6.1) | 0.88% | — | Ari-soft ARI Fancy Lightbox | 14/3/2022 | 17/6/2026 | The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.62% | — | Simplygallery Simply Gallery Blocks With Lightbox | 30/8/2021 | 17/6/2026 | A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.0 & below). The vulnerability exists in the Lightbox functionality where a user with low privileges is allowed to execute arbitrary script code within the context of the application. This… | |
| Modificada | Media (5.4) | 0.62% | — | Tipsandtricks-hq WP Video Lightbox | 30/8/2021 | 17/6/2026 | The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.52% | — | 23systems Lightbox Plus Colorbox | 9/8/2019 | 17/6/2026 | The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS. | |
| Modificada | Media (6.1) | 1.5% | — | Dfactory Responsive Lightbox | 7/7/2017 | 17/6/2026 | Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 1.0% | — | Lightbox Photo Gallery Project Lightbox Photo Gallery | 2/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting (XSS) attacks via the (2)… | |
| Modificada | Media (4.3) | 1.0% | — | Julian Kleinhans KJ Imagelightbox2 | 15/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the KJ: Imagelightbox (kj_imagelightbox2) extension 2.0.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-2490. | |
| Modificada | Media (4.3) | 1.0% | — | Typo3 KJ Imagelightbox2 | 28/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the KJ Image Lightbox 2 (aka kj_imagelightbox2) extension 1.4.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified "user input." |