Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
2404 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 2.9% | — | Newfold WP Module DataAINewfold WP Plugin Crazy DomainsAINewfold WP Plugin WEBAINewfold WP Plugin HostgatorAI+1 | 9/9/2026 | 9/9/2026 | Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request —… | |
| Aplazada | Media (5.9) | 0.23% | — | Paymentplugins Payment Plugins FOR Paypal WoocommerceAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then charge or delete it. Exploitation requires… | |
| Aplazada | Media (5.3) | 0.34% | — | Payment Plugins FOR Paypal WoocommerceAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the secret that gates access to any order and, through it, that customer's billing and… | |
| Aplazada | Media (5.3) | 0.34% | — | Paymentpluginsforstripe Payment Plugins FOR StripeAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by… | |
| Pendiente de análisis | Baja (2.1) | 0.10% | — | Android WatchAIAndroid Watch PluginAI | 9/9/2026 | 10/9/2026 | Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information. | |
| Aplazada | Media (5.4) | 0.21% | — | Booking-wp-plugin BooklyAI | 8/9/2026 | 8/9/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (7.1) | 0.25% | — | 100plugins Open User MAPAI | 8/9/2026 | 8/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions. | |
| Aplazada | Alta (7.2) | 0.27% | — | Wpplugins Hide MY WP GhostAI | 8/9/2026 | 8/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09. | |
| Aplazada | Alta (7.5) | 0.21% | — | Verygoodplugins WP FusionAI | 7/9/2026 | 8/9/2026 | The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.7) | 0.39% | — | Getgrav Grav-plugin-apiAI | 5/9/2026 | 8/9/2026 | grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. A non-super user manager with api.access and api.users.write permissions can… | |
| Aplazada | Alta (8.7) | 0.36% | — | Getgrav Grav-plugin-apiAI | 5/9/2026 | 8/9/2026 | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control. | |
| Aplazada | Media (6.9) | 0.56% | — | Getgrav Grav Form PluginAI | 5/9/2026 | 18/9/2026 | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Pickplugins ComboblocksAI | 5/9/2026 | 8/9/2026 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress,… | |
| Aplazada | Media (6.4) | 0.42% | — | Fooplugins FoogalleryAI | 5/9/2026 | 8/9/2026 | The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Media (6.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 5/9/2026 | 8/9/2026 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who… | |
| Aplazada | Crítica (9.3) | 0.36% | — | Getgrav Grav-plugin-formAI | 4/9/2026 | 8/9/2026 | The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous attacker can place their v3 token under the v2 field name… | |
| Aplazada | Media (5.1) | 0.24% | — | Getgrav Grav-plugin-admin2AI | 4/9/2026 | 8/9/2026 | Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation templates before parsing the result as markdown. Grav's server-side username… | |
| Aplazada | Media (5.3) | 0.29% | — | Kings Plugins MarketkingAI | 4/9/2026 | 7/9/2026 | Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: from n/a through 2.1.60. | |
| Aplazada | Alta (7.1) | 0.25% | — | Fullworksplugins Quick Event ManagerAI | 3/9/2026 | 4/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fullworksplugins Quick Event ManagerAI | 3/9/2026 | 5/9/2026 | Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Jenkins Parameterized Remote Trigger PluginAI | 2/9/2026 | 3/9/2026 | Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Pendiente de análisis | Alta (7.4) | 1.2% | — | Jenkins Tics PluginAI | 2/9/2026 | 3/9/2026 | OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build. | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Jenkins Microsoft Entra ID PluginAI | 2/9/2026 | 3/9/2026 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group. | |
| Pendiente de análisis | Alta (8.8) | 0.83% | — | Jenkins File Parameter PluginAI | 2/9/2026 | 3/9/2026 | Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution. | |
| Pendiente de análisis | Alta (8.8) | 0.55% | — | Jenkins Allure PluginAI | 2/9/2026 | 3/9/2026 | A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system. |