Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.40% | — | Brainstormforce Starter Templates | 7/12/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4. | |
| Modificada | Alta (7.5) | 0.97% | 💥 PoC | Themeisle Cloud Templates & Patterns Collection | 23/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collection.This issue affects Cloud Templates & Patterns collection: from n/a through 1.2.2. | |
| Modificada | Media (6.1) | 0.41% | — | Ioannup Edit Woocommerce Templates | 16/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ioannup Edit WooCommerce Templates plugin <= 1.1.1 versions. | |
| Modificada | Alta (8.8) | 0.28% | — | Wpexperts Email Templates Customizer AND Designer | 7/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpexpertsio Email Templates Customizer and Designer for WordPress and WooCommerce email-templates allows Cross Site Request Forgery.This issue affects Email Templates Customizer and Designer for WordPress and WooCommerce: from n/a through 1.4.2. | |
| Modificada | Media (6.1) | 0.29% | — | Ericteubert Archivist - Custom Archive Templates | 27/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions. | |
| Modificada | Alta (8.8) | 1.2% | — | Wpexperts Email Templates | 7/6/2023 | 17/6/2026 | The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers to present phishing forms or conduct cross-site request forgery attacks against site administrators. | |
| Modificada | Alta (8.8) | 0.26% | — | Brainstormforce Starter Templates | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Archivist - Custom Archive Templates Project Archivist - Custom Archive Templates | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Templatesnext Toolkit | 23/3/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TemplatesNext TemplatesNext ToolKit plugin <= 3.2.7 versions. | |
| Modificada | Alta (7.5) | 1.0% | — | Swig-templates Project Swig-templatesSwig Project Swig | 15/3/2023 | 17/6/2026 | Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags. | |
| Modificada | Crítica (9.8) | 1.0% | — | Swig-templates Project Swig-templatesSwig Project Swig | 15/3/2023 | 17/6/2026 | An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.prototype anonymous function. | |
| Modificada | Media (5.4) | 0.49% | — | Templatesnext Toolkit | 13/2/2023 | 17/6/2026 | The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using them to generate an HTML tag, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.54% | — | Templatesnext Toolkit | 13/2/2023 | 17/6/2026 | The TemplatesNext ToolKit WordPress plugin before 3.2.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 0.92% | — | Kadencewp Starter Templates | 9/1/2023 | 17/6/2026 | The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | |
| Modificada | Crítica (9.8) | 1.5% | — | Pebbletemplates Pebble Templates | 12/9/2022 | 17/6/2026 | Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary Java code, and thus either the input should not arrive from an untrusted source,… | |
| Modificada | Media (5.5) | 0.25% | — | Openstack Tripleo Heat Templates | 26/8/2022 | 17/6/2026 | A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager. | |
| Modificada | Media (4.3) | 0.79% | — | Openstack Tripleo Heat TemplatesRedhat Openstack | 23/3/2022 | 17/6/2026 | An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to all end users) in configuration files. This would give sensitive information which may aid… | |
| Modificada | Media (5.4) | 0.60% | — | Brainstormforce Starter Templates | 17/11/2021 | 17/6/2026 | On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious… | |
| Modificada | Media (5.4) | 0.56% | — | Apollo13themes Rife Elementor Extensions & Templates | 5/5/2021 | 17/6/2026 | The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Alta (8.8) | 1.6% | — | Cyberchimps Gutenberg & Elementor Templates Importer FOR Responsive | 23/4/2020 | 17/6/2026 | The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests. | |
| Modificada | Crítica (9.8) | 1.3% | — | Pebbletemplates Pebble Templates | 19/12/2019 | 17/6/2026 | Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature. | |
| Modificada | Alta (8.8) | 0.89% | — | Redhat OpenstackOpenstack Tripleo Heat Templates | 30/7/2018 | 17/6/2026 | A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials. | |
| Modificada | Media (6.1) | 0.71% | — | IBM Social Rendering Templates FOR Digital Data Connector | 1/2/2017 | 17/6/2026 | IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Alta (7.5) | 2.4% | — | Redhat OpenstackOpenstack Tripleo Heat Templates | 15/4/2016 | 17/6/2026 | The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private… | |
| Modificada | Alta (7.5) | 1.7% | — | Openstack Tripleo Heat Templates | 11/4/2016 | 17/6/2026 | The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter. |