Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.96% | — | Tonjoostudio Fluid-responsive-slideshow | 17/9/2019 | 17/6/2026 | The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has reflected XSS via the skin parameter. | |
| Modificada | Alta (8.8) | 0.73% | — | Tonjoostudio Fluid-responsive-slideshow | 17/9/2019 | 17/6/2026 | The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS. | |
| Modificada | Media (6.1) | 1.0% | — | Tribulant Slideshow Gallery | 15/4/2019 | 17/6/2026 | XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter. | |
| Modificada | Crítica (9.8) | 2.2% | — | Tribulant Slideshow Gallery | 15/4/2019 | 17/6/2026 | SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter. | |
| Modificada | Media (6.1) | 1.0% | — | Tribulant Slideshow Gallery | 15/4/2019 | 17/6/2026 | XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter. | |
| Modificada | Media (6.1) | 0.84% | — | Tribulant Slideshow Gallery | 3/10/2018 | 17/6/2026 | The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter. | |
| Modificada | Crítica (9.8) | 2.9% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter. | |
| Modificada | Crítica (9.8) | 2.9% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter. | |
| Modificada | Crítica (9.8) | 2.9% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php. | |
| Modificada | Crítica (9.8) | 3.4% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement. | |
| Modificada | Media (5.4) | 0.98% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database. | |
| Modificada | Alta (7.5) | 0.64% | — | Socusoft Flash Slideshow Maker | 5/8/2017 | 17/6/2026 | SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues. | |
| Modificada | Alta (7.5) | 3.5% | — | Slideshow Project Slideshow | 8/6/2017 | 17/6/2026 | The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values. | |
| Modificada | Alta (7.2) | 2.3% | — | Huge-it Slideshow | 21/10/2016 | 17/6/2026 | XSS & SQLi in HugeIT slideshow v1.0.4 | |
| Modificada | Alta (7.2) | 2.3% | — | Huge-it Slideshow | 21/10/2016 | 17/6/2026 | XSS & SQLi in HugeIT slideshow v1.0.4 | |
| Modificada | Alta (7.5) | 4.8% | — | Wpslideshow Powerplay Gallery | 18/8/2015 | 17/6/2026 | Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in *_uploadfolder/big/. | |
| Modificada | Media (6.8) | 1.0% | — | Gslideshow Project Gslideshow | 31/12/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the gSlideShow plugin 0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) rss, (2) display_time or (3) transistion_time parameter in the… | |
| Modificada | Media (6.5) | 3.2% | — | Gb-plugins GB Gallery Slideshow | 21/10/2014 | 17/6/2026 | SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQL commands via the selected_group parameter in a gb_ajax_get_group action to wp-admin/admin-ajax.php. | |
| Modificada | Media (5.4) | 0.27% | — | Grassapper Slideshow 365 | 17/9/2014 | 17/6/2026 | The Slideshow 365 (aka com.Slideshow) application 3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.5) | 71% | — | Tribulant Tibulant Slideshow Gallery | 11/9/2014 | 17/6/2026 | Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/. | |
| Modificada | Media (4.3) | 2.0% | — | Opensource Technologies Responsive Logo Slideshow | 14/3/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Responsive Logo Slideshow plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the "URL and Image" field. | |
| Modificada | Media (4.3) | 3.7% | — | Wordpress Slideshow Gallery2 | 1/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the border parameter. | |
| Modificada | Media (6.8) | 1.2% | — | Ubiquity Slideshow Team Ubiquity-slideshow-ubuntu | 28/9/2012 | 16/6/2026 | ubiquity-slideshow-ubuntu before 58.2, during installation, allows remote man-in-the-middle attackers to execute arbitrary web script or HTML and read arbitrary files via a crafted attribute in the <a> tag of a Twitter feed. | |
| Modificada | Alta (7.5) | 2.3% | — | Wpslideshow Image News Slider | 14/8/2012 | 16/6/2026 | Unspecified vulnerability in the Image News slider plugin before 3.3 for WordPress has unspecified impact and remote attack vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Webmaster-tips COM Slideshow | 9/10/2011 | 16/6/2026 | SQL injection vulnerability in the Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. |