Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
157 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.33% | — | Cusrev Customer Reviews FOR Woocommerce | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce customer-reviews-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for WooCommerce: from n/a through <= 5.36.0. | |
| Aplazada | Alta (7.1) | 0.44% | — | Revidev Revi-io-customer-and-product-reviewsAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revidev Revi.io revi-io-customer-and-product-reviews allows Reflected XSS.This issue affects Revi.io: from n/a through <= 5.7.3. | |
| Aplazada | Media (5.3) | 0.50% | — | Geminilabs Site ReviewsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through <= 6.10.2. | |
| Aplazada | Media (5.3) | 0.50% | — | Stamped.io Product Reviews & UGC FOR WoocommerceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Stamped.io Stamped.io Product Reviews & UGC for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stamped.io Product Reviews & UGC for WooCommerce: from n/a through 2.3.2. | |
| Aplazada | Media (4.3) | 0.40% | — | Geminilabs Site ReviewsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Paul Ryley Site Reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 6.5.0. | |
| Aplazada | Media (5.4) | 0.52% | — | Noah Hearle Reviews AND Rating Google MY BusinessAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Noah Hearle, Design Extreme Reviews and Rating – Google My Business allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reviews and Rating – Google My Business: from n/a through 4.14. | |
| Analizada | Media (4.3) | 0.28% | — | Cusrev Customer Reviews FOR Woocommerce | 16/11/2024 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel and import… | |
| Modificada | Media (5.4) | 0.32% | — | Shopitpress SIP Reviews Shortcode FOR Woocommerce | 31/10/2024 | 17/6/2026 | The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Modificada | Media (6.5) | 0.49% | — | Shopitpress SIP Reviews Shortcode FOR Woocommerce | 31/10/2024 | 17/6/2026 | The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Analizada | Media (5.4) | 0.31% | — | Codesupply Absolute Reviews | 27/9/2024 | 17/6/2026 | The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom post criteria in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Analizada | Crítica (9.8) | 1.6% | — | Villatheme Woocommerce Photo Reviews | 11/9/2024 | 17/6/2026 | The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating what user transient is being used in the login() function and not properly verifying the user's identity. This makes it… | |
| Analizada | Media (4.3) | 0.23% | — | Smashballoon Reviews Feed | 27/8/2024 | 17/6/2026 | The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'update_api_key' function. This makes it… | |
| Analizada | Media (4.3) | 0.40% | — | Smashballoon Reviews Feed | 27/8/2024 | 17/6/2026 | The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_api_key' function in all versions up to, and including, 1.1.2. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.31% | — | Reviews.co.uk Reviews.ioAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Reviews.Co.Uk REVIEWS.Io allows Stored XSS.This issue affects REVIEWS.Io: from n/a through 1.2.7. | |
| Aplazada | Media (4.3) | 0.28% | — | Saleswonder GET Better Reviews FOR WoocommerceAI | 12/7/2024 | 17/6/2026 | Missing Authorization vulnerability in Saleswonder Team: Tobias Get Better Reviews for WooCommerce more-better-reviews-for-woocommerce.This issue affects Get Better Reviews for WooCommerce: from n/a through <= 4.0.6. | |
| Aplazada | Media (5.3) | 0.37% | — | Saleswonder Builder FOR Woocommerce Reviews Shortcodes ReviewshortAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Saleswonder Team: Tobias Builder for WooCommerce reviews shortcodes – ReviewShort woo-product-reviews-shortcode.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through <= 1.01.5. | |
| Analizada | Crítica (9.1) | 0.56% | — | Geminilabs Site Reviews | 29/5/2024 | 17/6/2026 | The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking | |
| Aplazada | Media (6.4) | 0.38% | — | Reviews AND Rating Google ReviewsAI | 25/5/2024 | 17/6/2026 | The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | |
| Aplazada | Media (6.5) | 0.37% | 💥 PoC | Kemory Grubb Recencio-book-reviewsAI | 29/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemory Grubb Recencio Book Reviews recencio-book-reviews allows DOM-Based XSS.This issue affects Recencio Book Reviews: from n/a through <= 1.66.0. | |
| Aplazada | Media (4.3) | 0.34% | — | Implecode Reviews PlusAI | 26/4/2024 | 17/6/2026 | Missing Authorization vulnerability in impleCode Reviews Plus.This issue affects Reviews Plus: from n/a through 1.3.4. | |
| Modificada | Media (6.1) | 0.37% | — | Cusrev Customer Reviews FOR Woocommerce | 19/4/2024 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Modificada | Media (4.3) | 0.45% | — | Cusrev Customer Reviews FOR Woocommerce | 16/4/2024 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes. | |
| Modificada | Media (4.3) | 0.43% | — | Cusrev Customer Reviews FOR Woocommerce | 16/4/2024 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send… | |
| Analizada | Media (5.4) | 0.50% | — | Gowebsolutions WP Customer Reviews | 15/4/2024 | 17/6/2026 | The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL | |
| Aplazada | Alta (8) | 0.53% | — | Trustindex Widgets FOR Google ReviewsAI | 26/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2. |