Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.73%—Tipsandtricks-hq WP Video Lightbox25/7/202217/6/2026
The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
ModificadaMedia (6.1)0.80%—I13websolution Team Circle Image Slider With Lightbox14/3/202217/6/2026
The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
ModificadaMedia (6.1)0.88%—Ari-soft ARI Fancy Lightbox14/3/202217/6/2026
The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (5.4)0.62%—Simplygallery Simply Gallery Blocks With Lightbox30/8/202117/6/2026
A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.0 & below). The vulnerability exists in the Lightbox functionality where a user with low privileges is allowed to execute arbitrary script code within the context of the application. This…
ModificadaMedia (5.4)0.62%—Tipsandtricks-hq WP Video Lightbox30/8/202117/6/2026
The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
ModificadaMedia (6.1)0.52%—23systems Lightbox Plus Colorbox9/8/201917/6/2026
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.
ModificadaMedia (6.1)1.5%—Dfactory Responsive Lightbox7/7/201717/6/2026
Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)1.0%—Lightbox Photo Gallery Project Lightbox Photo Gallery2/1/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting (XSS) attacks via the (2)…
ModificadaMedia (4.3)1.0%—Julian Kleinhans KJ Imagelightbox215/1/201016/6/2026
Cross-site scripting (XSS) vulnerability in the KJ: Imagelightbox (kj_imagelightbox2) extension 2.0.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-2490.
ModificadaMedia (4.3)1.0%—Typo3 KJ Imagelightbox228/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in the KJ Image Lightbox 2 (aka kj_imagelightbox2) extension 1.4.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified "user input."
Orbitaley — Vulnerabilidades