Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.34% | — | Onion-site-templateAI | 6/8/2025 | 17/6/2026 | onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing onion domain. A website could be compromised if a user shared the baked-in image, or if someone were able to acquire access… | |
| Aplazada | Media (6.5) | 0.32% | 💥 PoC | Writebot AI Content Generator Saas React TemplateAI | 5/8/2025 | 5/7/2026 | File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request to the /file-upload endpoint. | |
| Aplazada | Crítica (9.8) | 0.36% | — | Flask-boilerplateAI | 7/7/2025 | 17/6/2026 | flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header. | |
| Analizada | Baja (2.4) | 0.15% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code. | |
| Analizada | Media (4.6) | 0.24% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system. | |
| Analizada | Media (6.8) | 0.25% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control. | |
| Analizada | Media (4.3) | 0.14% | — | Themebon Digital Marketing AND Agency Templates Addons FOR Elementor | 13/6/2025 | 17/6/2026 | The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the import_templates() function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.9) | 0.26% | — | Otowthemes Post Custom Templates LiteAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Post Custom Templates Lite post-custom-templates-lite allows Stored XSS.This issue affects Post Custom Templates Lite: from n/a through <= 1.14. | |
| Aplazada | Crítica (10) | 4.6% | 💥 Exploit | Templateinvaders TI Woocommerce WishlistAI | 19/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Upload a Web Shell to a Web Server.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.9.2. | |
| Aplazada | Media (6.5) | 0.24% | — | Templateinvaders TI Woocommerce WishlistAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Stored XSS.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.10.0. | |
| Aplazada | Alta (7.2) | 0.76% | — | ADD Custom Page TemplateAI | 26/4/2025 | 17/6/2026 | The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'acpt_validate_setting' function. This is due to insufficient sanitization of the 'template_name' parameter. This makes it possible for… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Webbytemplate Office LocatorAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Office Locator office-locator allows SQL Injection.This issue affects Office Locator: from n/a through <= 1.3.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Aakif Kadiwala Event Espresso - Custom Email Template ShortcodeAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Event Espresso – Custom Email Template Shortcode email-shortcode allows Reflected XSS.This issue affects Event Espresso – Custom Email Template Shortcode: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.36% | — | Fbtemplates Nemesis-all-in-oneAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fbtemplates Nemesis All-in-One nemesis-all-in-one allows Stored XSS.This issue affects Nemesis All-in-One: from n/a through <= 1.1.3. | |
| Aplazada | Media (6.5) | 0.36% | — | Otwthemes Post Custom Templates LiteAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Post Custom Templates Lite post-custom-templates-lite allows Stored XSS.This issue affects Post Custom Templates Lite: from n/a through <= 1.14. | |
| Analizada | Alta (8.6) | 2.4% | ⚠ Explotación activa | Reviewdog Action-ast-grepReviewdog Action-composite-templateReviewdog Action-setupReviewdog Action-shellcheck+2 | 19/3/2025 | 17/6/2026 | reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be… | |
| Analizada | Alta (8.8) | 0.36% | — | Irontemplates Soundrise | 14/3/2025 | 17/6/2026 | The SoundRise Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on theironMusic_ajax() function in all versions up to, and including, 1.6.11. This makes it possible for authenticated attackers, with subscriber-level… | |
| Aplazada | Media (4.3) | 0.17% | — | A Chappard Display Template NameAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in A. Chappard Display Template Name display-template-name allows Cross Site Request Forgery.This issue affects Display Template Name: from n/a through <= 1.7.1. | |
| Modificada | Media (4.8) | 0.28% | — | Shanebp BP Email Assign Templates | 11/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Stored XSS.This issue affects BP Email Assign Templates: from n/a through <= 1.6. | |
| Modificada | Media (4.9) | 0.45% | — | Shanebp BP Email Assign Templates | 11/3/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Email Assign Templates: from n/a through <= 1.7. | |
| Analizada | Crítica (9.1) | 0.43% | — | Fancywp Starter Templates | 8/3/2025 | 17/6/2026 | The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 via the 'http_request_host_is_external' filter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web… | |
| Aplazada | Alta (8.6) | 0.31% | — | Wind Media E-commerce Website TemplateAI | 4/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Commerce Website Template allows SQL Injection. This issue affects E-Commerce Website Template: before v1.5. | |
| Aplazada | Media (6.4) | 0.26% | — | Templatesnext ToolkitAI | 1/3/2025 | 17/6/2026 | The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wishlist_table' shortcode in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (4.8) | 0.85% | — | Pebbletemplates Pebble Templates | 27/2/2025 | 17/6/2026 | Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A high privileged attacker can access sensitive local files by crafting malicious notification templates that leverage this tag to include files like /etc/passwd or… | |
| Analizada | Media (5.4) | 0.30% | — | Apollo13 Rife Elementor Extensions & Templates | 22/2/2025 | 17/6/2026 | The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |