Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.56% | — | Testimonials Project Testimonials | 22/7/2022 | 17/6/2026 | Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Chinmoy Paul's Testimonials plugin <= 3.0.1 at WordPress. | |
| Modificada | Alta (8.8) | 1.6% | — | Handsome Testimonials & Reviews Project Handsome Testimonials & Reviews | 2/8/2021 | 17/6/2026 | The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue. | |
| Modificada | Media (5.4) | 0.82% | — | Axelerant Testimonials Widget | 18/3/2021 | 17/6/2026 | Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below parameters: - Author - Job Title - Location - Company - Email - URL | |
| Modificada | Media (5.4) | 0.89% | — | Goldplugins Easy Testimonials | 22/6/2020 | 17/6/2026 | Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, Web Address, Other, Location Reviewed, Product Reviewed, Item Reviewed, or Rating parameter. | |
| Modificada | Media (6.1) | 1.9% | — | Wpchill Strong Testimonials | 3/2/2020 | 17/6/2026 | Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens. | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Hitmyserver HMS Testimonials | 30/1/2020 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form (hms-testimonials-addnew page); (5) date_format… | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Bestwebsoft Testimonials | 21/8/2019 | 17/6/2026 | The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.93% | — | Goldplugins Easy Testimonials | 26/11/2018 | 17/6/2026 | Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting. | |
| Modificada | Media (6.1) | 0.78% | — | Goldplugins Easy Testimonials | 1/8/2017 | 17/6/2026 | The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonials Width, View More Testimonials Link, and Testimonial Excerpt Options screens. | |
| Modificada | Alta (8.8) | 2.4% | 💥 Exploit | Goldplugins Testimonials Plugin Easy Testimonials | 12/6/2017 | 17/6/2026 | SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/admin.php. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Media (6.8) | 2.8% | 💥 Exploit | Hitmyserver HMS Testimonials | 2/4/2014 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add new testimonials via the hms-testimonials-addnew page, (2) add new groups via the… | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Oscommerce Customer TestimonialsOscommerce | 12/2/2008 | 16/6/2026 | SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter. |