Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.32% | — | Theresehansen Commenttweets | 8/1/2024 | 17/6/2026 | The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | |
| Modificada | Alta (8.8) | 0.27% | — | Gvectors Woodiscuz - Woocommerce Comments | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0. | |
| Modificada | Alta (7.5) | 0.43% | — | Sean-barton Commentluv | 15/12/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Elegant Digital Solutions CommentLuv.This issue affects CommentLuv: from n/a through 3.0.4. | |
| Modificada | Alta (8.8) | 0.25% | — | Supremo Bulk Comment Remove | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mike Strand Bulk Comment Remove allows Cross Site Request Forgery.This issue affects Bulk Comment Remove: from n/a through 2. | |
| Modificada | Crítica (9.8) | 0.85% | — | Webtoffee Wordpress Comments Import AND Export | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.1. | |
| Modificada | Crítica (9.8) | 0.61% | — | Coffee2code Commenter Emails | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Scott Reilly Commenter Emails.This issue affects Commenter Emails: from n/a through 2.6.1. | |
| Modificada | Media (4.8) | 0.32% | — | Pixelgrade Comments Rating | 6/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions. | |
| Modificada | Crítica (9.8) | 0.55% | — | Appjetty Copy OR Move Comments | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in biztechc Copy or Move Comments allows SQL Injection.This issue affects Copy or Move Comments: from n/a through 5.0.4. | |
| Modificada | Media (6.1) | 0.39% | — | Appjetty Copy OR Move Comments | 25/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Biztechc Copy or Move Comments plugin <= 5.0.4 versions. | |
| Modificada | Media (4.8) | 0.32% | — | Wpjohnny Comment Reply Email | 18/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPJohnny Comment Reply Email plugin <= 1.0.3 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Pixelgrade Comments Rating | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions. | |
| Modificada | Media (4.3) | 0.93% | 💥 PoC | Wphappycoders Comments Like Dislike | 17/8/2023 | 17/6/2026 | The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers with minimal permissions, such as a… | |
| Modificada | Media (4.3) | 0.56% | — | Vuukle Comments, Reactions, Share Bar, Revenue | 12/7/2023 | 17/6/2026 | The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wordpress-vuukle-admin-display.php file. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.26% | — | Comment Reply Notification Project Comment Reply Notification | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Denishua Comment Reply Notification plugin <= 1.4 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Pixelgrade Comments Rating | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.6 versions. | |
| Modificada | Media (5.3) | 0.46% | — | Palantir Foundry Comments | 10/7/2023 | 17/6/2026 | A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0. | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Heator Social Share, Social Login AND Social Comments | 19/6/2023 | 17/6/2026 | The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Crítica (9.8) | 2.3% | — | Delete ALL Comments Project Delete ALL Comments | 7/6/2023 | 17/6/2026 | The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-comments.php file in versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which… | |
| Modificada | Media (6.5) | 0.54% | — | Palantir Foundry Comments | 6/6/2023 | 17/6/2026 | A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorization checks. This could enable an authenticated user to inject a prior discovered attachment UUID into other arbitrary comments to discover it's content. This defect was… | |
| Modificada | Media (5.4) | 0.36% | — | Display Post Meta, Term Meta, Comment Meta, AND User Meta Project Display Post Meta, Term Meta, Comment Meta, AND User Meta | 31/5/2023 | 17/6/2026 | The Display post meta, term meta, comment meta, and user meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post metadata in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.8) | 0.37% | — | Gvectors Woodiscuz - Woocommerce Comments | 28/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.2.9. | |
| Modificada | Media (6.1) | 0.56% | — | Comment System Project Comment System | 27/5/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Comment System 1.0. Affected is an unknown function of the file index.php of the component GET Parameter Handler. The manipulation of the argument msg leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Media (4.8) | 0.37% | — | Lazy Social Comments Project Lazy Social Comments | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Lazy Social Comments plugin <= 2.0.4 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Heateor Social Comments | 4/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin for Vkontakte Comments and Disqus Comments plugin <= 1.6.1 versions. |