Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.22% | — | Thorsten OTT Debug-bar-extenderAI | 15/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thorsten Ott Debug-Bar-Extender debug-bar-extender allows Reflected XSS.This issue affects Debug-Bar-Extender: from n/a through <= 0.5. | |
| Aplazada | Alta (7.1) | 0.30% | — | Willshouse Tinymce-extended-configAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willshouse TinyMCE Extended Config tinymce-extended-config allows Reflected XSS.This issue affects TinyMCE Extended Config: from n/a through <= 0.1.0. | |
| Analizada | Media (5.3) | 0.31% | — | Wpextended WP Extended | 12/2/2025 | 17/6/2026 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reorder_route() function in all versions up to, and including, 3.0.13. This makes it possible for unauthenticated attackers to reorder posts. | |
| Aplazada | Crítica (9.8) | 0.66% | — | Nextend Social Login PROAI | 7/2/2025 | 17/6/2026 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.16. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.1) | 0.49% | — | Utils-extendAI | 5/2/2025 | 17/6/2026 | The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) a the minimum consequence. | |
| Aplazada | Media (5.5) | 0.20% | — | Sonicwall NetextenderAI | 30/1/2025 | 17/6/2026 | A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation. | |
| Aplazada | Alta (7.5) | 0.54% | 💥 PoC | Wpextended WP ExtendedAI | 18/1/2025 | 17/6/2026 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including, 3.0.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Analizada | Media (5.4) | 0.21% | — | Wpextended WP Extended | 8/1/2025 | 17/6/2026 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on several functions in all versions up to, and including, 3.0.11. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Analizada | Alta (8.8) | 0.75% | — | Wpextended Ultimate Wordpress Toolkit | 8/1/2025 | 17/6/2026 | The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing capability check on the 'wpext_handle_snippet_update' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute… | |
| Aplazada | Media (4.3) | 0.18% | — | Extendthemes HighlightAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in extendthemes Highlight highlight allows Cross Site Request Forgery.This issue affects Highlight: from n/a through <= 1.0.29. | |
| Aplazada | Media (4.3) | 0.18% | — | Extendthemes MesmerizeAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in extendthemes Mesmerize mesmerize allows Cross Site Request Forgery.This issue affects Mesmerize: from n/a through <= 1.6.120. | |
| Modificada | Crítica (9.8) | 0.66% | — | Xtendify Woffice | 16/12/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice woffice allows Authentication Bypass.This issue affects Woffice: from n/a through <= 5.4.14. | |
| Aplazada | Media (5.4) | 0.34% | — | Felixwelberg Extended Post StatusAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Felix Welberg Extended Post Status allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extended Post Status: from n/a through 1.0.19. | |
| Aplazada | Alta (7.1) | 0.17% | — | Realtycandy IDX Broker ExtendedAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RealtyCandy.com RealtyCandy IDX Broker Extended realtycandy-idx-broker-extended allows Stored XSS.This issue affects RealtyCandy IDX Broker Extended: from n/a through <= 1.5.1. | |
| Aplazada | Media (6.4) | 0.42% | — | BNE Gallery ExtendedAI | 26/11/2024 | 17/6/2026 | The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.31% | — | Wp-orphanage Extended WP Orphanage ExtendedAI | 23/11/2024 | 17/6/2026 | The WP-Orphanage Extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the wporphanageex_menu_settings() function. This makes it possible for unauthenticated attackers to escalate the privileges of… | |
| Aplazada | Alta (7.1) | 0.41% | — | Jerin K Alexander Events Manager PRO ExtendedAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jerin K Alexander Events Manager Pro – extended events-manager-pro-extended allows Reflected XSS.This issue affects Events Manager Pro – extended: from n/a through <= 0.1. | |
| Aplazada | Media (6.5) | 0.25% | — | MD Abdullah AL Masum Extender ALL IN ONE FOR ElementorAI | 11/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Abdullah Al Masum Extender All In One For Elementor extender-all-in-one-for-elementor allows Stored XSS.This issue affects Extender All In One For Elementor: from n/a through <= 1.0.3. | |
| Analizada | Crítica (9.8) | 0.50% | — | Xtendify Woffice | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WofficeIO Woffice Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woffice Core: from n/a through 5.4.8. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpseek Admin Management XtendedAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpseek Admin Management Xtended admin-management-xtended allows Stored XSS.This issue affects Admin Management Xtended : from n/a through <= 2.4.6. | |
| Modificada | Media (6.1) | 0.49% | — | Wpextended WP Extended | 17/10/2024 | 17/6/2026 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpext-export' parameter in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Nextend Social Login PROAI | 16/10/2024 | 17/6/2026 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Aplazada | Crítica (10) | 0.55% | — | Sunjianle Ajax-extendAI | 16/10/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in sunjianle ajax-extend ajax-extend allows Code Injection.This issue affects ajax-extend: from n/a through <= 1.0. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Webextends Telecash RicaricawebAI | 16/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through <= 2.2. | |
| Aplazada | Alta (7.1) | 0.32% | — | Wpextended WP ExtendedAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended wpextended allows Reflected XSS.This issue affects The Ultimate WordPress Toolkit – WP Extended: from n/a through <= 3.0.8. |