Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
118 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.6) | 0.46% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request. | |
| Analizada | Alta (7.6) | 0.58% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request. | |
| Analizada | Media (5.5) | 0.18% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php. | |
| Aplazada | Alta (8) | 0.37% | — | Wpforms User RegistrationAI | 1/8/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Registration: from n/a through 2.1.0. | |
| Aplazada | Alta (7.1) | 0.33% | — | Wpeverest User RegistrationAI | 1/6/2024 | 17/6/2026 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_form_action' function in versions up to, and including, 3.2.0.1. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.91% | — | Wpeverest User RegistrationAI | 2/5/2024 | 17/6/2026 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the profile_pic_remove function in versions up to, and including, 3.1.5. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.94% | — | Wpeverest User RegistrationAI | 2/5/2024 | 17/6/2026 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the form_save_action() function in all versions up to, and including, 3.1.5. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.61% | — | Wpeverest User Registration & Membership | 26/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1. | |
| Analizada | Media (6.5) | 0.41% | — | Phpgurukul User Registration & Login AND User Management System | 14/3/2024 | 17/6/2026 | The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks. | |
| Analizada | Media (6.5) | 0.55% | — | Strategy11 User Registration Forms | 11/3/2024 | 17/6/2026 | The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and leak, valid password reset URLs, which they can use to take over any accounts. | |
| Modificada | Media (6.1) | 0.55% | — | Wpeverest User Registration & Membership | 7/3/2024 | 17/6/2026 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Media (6.1) | 0.99% | 💥 PoC | Phpgurukul User Registration & Login AND User Management System | 28/2/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar. | |
| Modificada | Crítica (9.8) | 0.80% | — | Remyandrade User Registration AND Login System | 2/12/2023 | 17/6/2026 | A vulnerability was found in SourceCodester User Registration and Login System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /endpoint/add-user.php. The manipulation of the argument user leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.60% | — | Remyandrade User Registration AND Login System | 1/12/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester User Registration and Login System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-user.php. The manipulation of the argument first_name leads to cross site scripting. The attack can be launched… | |
| Modificada | Media (6.1) | 0.61% | — | Remyandrade User Registration AND Login System | 1/12/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester User Registration and Login System 1.0. Affected is an unknown function of the file /endpoint/delete-user.php. The manipulation of the argument user leads to cross site scripting. It is possible to launch the attack remotely. The exploit… | |
| Modificada | Media (4.8) | 0.56% | — | Wpeverest User Registration | 6/11/2023 | 17/6/2026 | The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Crítica (9.8) | 0.81% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 16/10/2023 | 17/6/2026 | SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page. | |
| Modificada | Media (5.4) | 0.37% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 16/10/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the user registration page. | |
| Modificada | Alta (8.8) | 1.1% | — | Wpeverest User Registration | 13/7/2023 | 17/6/2026 | The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to inject a PHP Object. No POP chain is… | |
| Modificada | Crítica (9.9) | 1.7% | — | Wpeverest User Registration | 13/7/2023 | 17/6/2026 | The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with subscriber-level capabilities or… | |
| Modificada | Media (5.4) | 0.51% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 6/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field. | |
| Modificada | Media (6.1) | 0.41% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 29/6/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php. | |
| Modificada | Media (6.1) | 0.36% | — | User Registration & Login AND User Management System Project User Registration & Login AND User Management System | 21/6/2023 | 17/6/2026 | User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php. | |
| Modificada | Media (4.8) | 0.39% | — | Wpeverest User Registration | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin <= 2.3.0 versions. | |
| Modificada | Media (5.4) | 0.55% | — | Paidmembershipspro Custom User Profile Fields FOR User Registration | 30/1/2023 | 17/6/2026 | The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against… |