Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

103 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.96%—Tonjoostudio Fluid-responsive-slideshow17/9/201917/6/2026
The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has reflected XSS via the skin parameter.
ModificadaAlta (8.8)0.73%—Tonjoostudio Fluid-responsive-slideshow17/9/201917/6/2026
The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.
ModificadaMedia (6.1)1.0%—Tribulant Slideshow Gallery15/4/201917/6/2026
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter.
ModificadaCrítica (9.8)2.2%—Tribulant Slideshow Gallery15/4/201917/6/2026
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
ModificadaMedia (6.1)1.0%—Tribulant Slideshow Gallery15/4/201917/6/2026
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
ModificadaMedia (6.1)0.84%—Tribulant Slideshow Gallery3/10/201817/6/2026
The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter.
ModificadaCrítica (9.8)2.9%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.
ModificadaCrítica (9.8)2.9%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.
ModificadaCrítica (9.8)2.9%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.
ModificadaCrítica (9.8)3.4%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.
ModificadaMedia (5.4)0.98%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database.
ModificadaAlta (7.5)0.64%—Socusoft Flash Slideshow Maker5/8/201717/6/2026
SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues.
ModificadaAlta (7.5)3.5%—Slideshow Project Slideshow8/6/201717/6/2026
The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.
ModificadaAlta (7.2)2.3%—Huge-it Slideshow21/10/201617/6/2026
XSS & SQLi in HugeIT slideshow v1.0.4
ModificadaAlta (7.2)2.3%—Huge-it Slideshow21/10/201617/6/2026
XSS & SQLi in HugeIT slideshow v1.0.4
ModificadaAlta (7.5)4.8%—Wpslideshow Powerplay Gallery18/8/201517/6/2026
Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in *_uploadfolder/big/.
ModificadaMedia (6.8)1.0%—Gslideshow Project Gslideshow31/12/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the gSlideShow plugin 0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) rss, (2) display_time or (3) transistion_time parameter in the…
ModificadaMedia (6.5)3.2%—Gb-plugins GB Gallery Slideshow21/10/201417/6/2026
SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQL commands via the selected_group parameter in a gb_ajax_get_group action to wp-admin/admin-ajax.php.
ModificadaMedia (5.4)0.27%—Grassapper Slideshow 36517/9/201417/6/2026
The Slideshow 365 (aka com.Slideshow) application 3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.5)71%—Tribulant Tibulant Slideshow Gallery11/9/201417/6/2026
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.
ModificadaMedia (4.3)2.0%—Opensource Technologies Responsive Logo Slideshow14/3/201416/6/2026
Cross-site scripting (XSS) vulnerability in the Responsive Logo Slideshow plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the "URL and Image" field.
ModificadaMedia (4.3)3.7%—Wordpress Slideshow Gallery21/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the border parameter.
ModificadaMedia (6.8)1.2%—Ubiquity Slideshow Team Ubiquity-slideshow-ubuntu28/9/201216/6/2026
ubiquity-slideshow-ubuntu before 58.2, during installation, allows remote man-in-the-middle attackers to execute arbitrary web script or HTML and read arbitrary files via a crafted attribute in the <a> tag of a Twitter feed.
ModificadaAlta (7.5)2.3%—Wpslideshow Image News Slider14/8/201216/6/2026
Unspecified vulnerability in the Image News slider plugin before 3.3 for WordPress has unspecified impact and remote attack vectors.
ModificadaAlta (7.5)1.2%—Webmaster-tips COM Slideshow9/10/201116/6/2026
SQL injection vulnerability in the Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.