Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.25%—Emarketdesign Youtube Video Gallery3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in eMarket Design YouTube Video Gallery by YouTube Showcase plugin <= 3.3.5 versions.
ModificadaMedia (5.4)0.51%—Stefanoai Widget Responsive FOR Youtube20/9/202317/6/2026
The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortcode in versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaMedia (5.4)0.55%—Smashballoon Feeds FOR Youtube14/9/202317/6/2026
The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level…
ModificadaMedia (6.1)0.38%—Balasahebbhise Advanced Youtube Channel Pagination17/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Balasaheb Bhise Advanced Youtube Channel Pagination plugin <= 1.0 version.
ModificadaAlta (8.8)0.26%—Smart Youtube PRO Project Smart Youtube PRO18/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Vladimir Prelovac Smart YouTube PRO plugin <= 4.3 versions.
ModificadaAlta (8.2)1.0%—Youtube-dlc Project Youtube-dlcYt-dl Youtube-dlYt-dlp Project Yt-dlpFedoraproject Fedora6/7/202317/6/2026
yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs may leak cookies on HTTP redirects to a different host, or leak them when the host for download fragments differs from their parent manifest's host. This vulnerable…
ModificadaAlta (8.8)0.26%—Getbutterfly Youtube Playlist Player28/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <= 4.6.4 versions.
ModificadaAlta (8.8)0.26%—Secondlinethemes Auto Youtube Importer22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SecondLineThemes Auto YouTube Importer plugin <= 1.0.3 versions.
ModificadaMedia (5.4)0.36%—Simple Youtube Responsive Project Simple Youtube Responsive4/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Eirudo Simple YouTube Responsive plugin <= 2.5 versions.
ModificadaMedia (4.8)0.39%—Wpdevart Youtube Embed, Playlist AND Popup6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart YouTube Embed, Playlist and Popup by WpDevArt plugin <= 2.6.3 versions.
ModificadaAlta (7.3)0.11%—Google Youtube Android Player API1/3/202317/6/2026
The YouTube Embedded 1.2 SDK binds to a service within the YouTube Main App. After binding, a remote context is created with the flags Context.CONTEXT_INCLUDE_CODE | Context.CONTEXT_IGNORE_SECURITY. This allows the client app to remotely load code from YouTube Main App by retrieving the Main App’s ClassLoader. A…
ModificadaMedia (5.4)0.47%—Youtube Channel Gallery Project Youtube Channel Gallery13/2/202317/6/2026
The Youtube Channel Gallery WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.60%—MY Youtube Channel Project MY Youtube Channel6/2/202317/6/2026
The My YouTube Channel WordPress plugin before 3.23.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as…
ModificadaMedia (5.4)0.39%—Youtube Shortcode Project Youtube Shortcode23/1/202317/6/2026
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Youtube shortcode <= 1.8.5 versions.
ModificadaMedia (4.3)0.59%—MY Youtube Channel Project MY Youtube Channel23/1/202317/6/2026
The My YouTube Channel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the clear_all_cache function in versions up to, and including, 3.0.12.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to clear the plugin's cache.
ModificadaMedia (5.5)0.57%—MY Youtube Channel Project MY Youtube Channel23/1/202317/6/2026
The My YouTube Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 3.0.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…
ModificadaMedia (4.8)0.68%—WP Youtube Live Project WP Youtube Live16/5/202217/6/2026
The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (6.1)1.3%—Andrewrminion WP Youtube Live19/4/202217/6/2026
The WordPress WP YouTube Live Plugin is vulnerable to Reflected Cross-Site Scripting via POST data found in the ~/inc/admin.php file which allows unauthenticated attackers to inject arbitrary web scripts in versions up to, and including, 1.7.21.
ModificadaMedia (6.1)0.66%—Youtube-php-mirroring Project Youtube-php-mirroring29/11/202117/6/2026
youtube-php-mirroring (last update Jun 9, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php.
ModificadaMedia (5.4)0.62%—Video Player FOR Youtube Project Video Player FOR Youtube25/10/202117/6/2026
The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
ModificadaMedia (6.1)0.94%—Ueberhamm-design Youtube Video Inserter10/9/202117/6/2026
The YouTube Video Inserter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/adminUI/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.1.0.
ModificadaAlta (7.2)1.5%—Geekwebsolution Embed Youtube Video6/9/202117/6/2026
The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
ModificadaMedia (5.4)0.58%—Youtube Embed Project Youtube Embed16/8/202117/6/2026
The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, leading to Stored XSS issues by 1. using w, h, controls, cc_lang, color, language, start, stop, or style parameter of youtube shortcode, 2. by using style, class, rel, target, width, height, or alt…
ModificadaAlta (8.8)0.68%—Youtube Feeder Project Youtube Feeder5/8/202117/6/2026
The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in the ~/youtube-feeder.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.1.
ModificadaMedia (5.4)0.62%—Wpdevart Youtube Embed, Playlist AND Popup2/8/202117/6/2026
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue.
Orbitaley — Vulnerabilidades