Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.33% | — | Emarketdesign Employee Directory Staff Listing Team DirectoryAI | 28/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in emarket-design Employee Directory – Staff Listing & Team Directory Plugin for WordPress employee-directory allows Object Injection.This issue affects Employee Directory – Staff Listing & Team Directory Plugin for WordPress: from n/a through <= 4.5.5. | |
| Aplazada | Media (5.4) | 0.19% | — | Radiustheme Classified ListingAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RadiusTheme Classified Listing classified-listing allows Code Injection.This issue affects Classified Listing: from n/a through <= 5.0.0. | |
| Aplazada | Crítica (9.8) | 0.41% | — | Smartdatasoft Reveal ListingAI | 6/8/2025 | 17/6/2026 | The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'listing_user_role' field. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.1) | 0.26% | — | Gt3themes ListingeasyAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes ListingEasy listingeasy allows Reflected XSS.This issue affects ListingEasy: from n/a through <= 1.9.2. | |
| Analizada | Media (6.5) | 0.27% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 9/7/2025 | 17/6/2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcfm_redirect_to_setup function in all versions up to, and including, 6.7.16. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.56% | — | Radiustheme Classified ListingAI | 20/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This issue affects Classified Listing: from n/a through <= 4.2.0. | |
| Analizada | Media (4.8) | 0.31% | — | Realestateconnected Easy Property Listings | 15/5/2025 | 17/6/2026 | The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (6.1) | 0.33% | — | Smartdatasoft Clasify Classified Listing | 15/5/2025 | 17/6/2026 | The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Crítica (9.8) | 0.83% | — | Imithemes ListingAI | 9/5/2025 | 17/6/2026 | The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3. This is due to the plugin not properly validating a verification code value prior to updating their password through the imic_reset_password_init() function. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.57% | — | JOB ListingsAI | 3/5/2025 | 17/6/2026 | The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The plugin’s registration handler reads the client-supplied $_POST['user_role'] and passes it directly to wp_insert_user() without restricting to a… | |
| Aplazada | Alta (7.1) | 0.29% | — | Habibur Rahman Razib Control ListingsAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Habibur Rahman Razib Control Listings control-listings allows Reflected XSS.This issue affects Control Listings: from n/a through <= 1.0.4.1. | |
| Aplazada | Alta (8.8) | 0.48% | — | Stylemixthemes UlistingAI | 17/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <= 2.2.0. | |
| Aplazada | Alta (7.1) | 0.15% | — | Deepak Khokhar Listings FOR BuildiumAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Deepak Khokhar Listings for Buildium listings-for-buildium allows Stored XSS.This issue affects Listings for Buildium: from n/a through <= 0.1.5. | |
| Aplazada | Alta (7.1) | 0.29% | — | Radiustheme Classified ListingAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Classified Listing classified-listing allows Reflected XSS.This issue affects Classified Listing: from n/a through <= 4.0.1. | |
| Aplazada | Media (4.7) | 0.39% | — | Arthur Yarwood Fast Ebay ListingsAI | 16/4/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Arthur Yarwood Fast eBay Listings fast-ebay-listings allows Phishing.This issue affects Fast eBay Listings: from n/a through <= 2.12.15. | |
| Analizada | Media (4.3) | 0.31% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 8/4/2025 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all versions up to, and including, 1.4.66. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.22% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 8/4/2025 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.8) | 0.90% | 💥 PoC | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 8/4/2025 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.6) | 0.58% | — | Stylemixthemes UlistingAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing ulisting allows Blind SQL Injection.This issue affects uListing: from n/a through <= 2.2.0. | |
| Aplazada | Alta (7.1) | 0.14% | — | Listings FOR AppfolioAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Listings for Appfolio Listings for Appfolio listings-for-appfolio allows Stored XSS.This issue affects Listings for Appfolio: from n/a through <= 1.2.0. | |
| Analizada | Media (4.3) | 0.30% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 22/3/2025 | 17/6/2026 | The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. This makes it possible for authenticated attackers,… | |
| Modificada | Alta (8.8) | 0.43% | — | Stylemixthemes Ulisting | 15/3/2025 | 17/6/2026 | The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection due to a missing capability check on the stm_listing_ajax AJAX action in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.52% | — | Stylemixthemes Ulisting | 15/3/2025 | 17/6/2026 | The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This is due to the stm_listing_profile_edit AJAX action not having enough restriction on the user meta that can be updated. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.38% | — | Themographics ListingoAI | 5/3/2025 | 17/6/2026 | The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.3) | 0.41% | — | Stylemixthemes UlistingAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing ulisting allows Blind SQL Injection.This issue affects uListing: from n/a through <= 2.1.6. |