Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.43% | — | Verbb Comments | 5/6/2020 | 17/6/2026 | An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity. | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Livefyre Livecomments | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded picture. | |
| Modificada | Media (6.1) | 1.2% | — | Videowhisper Video Comments Webcam Recorder | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Media (6.5) | 1.1% | — | Jenkins Violation Comments TO Gitlab | 25/9/2019 | 17/6/2026 | Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (6.5) | 1.1% | — | Jenkins Violation Comments TO Gitlab | 25/9/2019 | 17/6/2026 | Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system. | |
| Modificada | Media (6.1) | 0.98% | — | Spot.im Comments | 10/9/2019 | 17/6/2026 | The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues. | |
| Modificada | Media (4.3) | 0.50% | — | Pippinsplugins Featured Comments | 22/8/2019 | 17/6/2026 | The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment. | |
| Modificada | Media (6.1) | 0.91% | — | Embed Images IN Comments Project Embed Images IN Comments | 21/8/2019 | 17/6/2026 | The embed-comment-images plugin before 0.6 for WordPress has XSS. | |
| Modificada | Alta (7.8) | 5.1% | 💥 Exploit | Webtoffee Wordpress Comments Import AND Export | 19/6/2018 | 17/6/2026 | The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. | |
| Modificada | Alta (8.8) | 1.6% | — | Disable Comments Project | 19/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that enable comments via a request to the disable_comments_settings page to wp-admin/options-general.php. | |
| Modificada | Alta (8.8) | 0.91% | — | Subscribe TO Comments Reloaded Project Subscribe TO Comments Reloaded | 19/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the… | |
| Modificada | Crítica (9.1) | 8.6% | — | Contussupport Contus-video-comments | 6/10/2016 | 17/6/2026 | Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin | |
| Modificada | Media (4.3) | 1.6% | — | Verification Code FOR Comments Project Verification Code FOR Comments | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm parameter. | |
| Modificada | Media (6.8) | 2.6% | 💥 Exploit | Featured Comments Plugin Project Featured Comments | 16/6/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that change the (1) buried or (2) featured status of a comment via a request to wp-admin/admin-ajax.php. | |
| Modificada | Media (4.3) | 2.1% | — | Mg12 Wp-recentcomments | 14/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging. | |
| Modificada | Alta (7.5) | 2.0% | — | Mg12 Wp-recentcomments | 14/2/2012 | 16/6/2026 | SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Joomlatune COM Jcomments | 23/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Raphael Zschorsch Commentsbe | 7/10/2011 | 16/6/2026 | SQL injection vulnerability in the Commenting system Backend Module (commentsbe) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Jxtended Comments | 9/12/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the JXtended Comments component before 1.3.1 for Joomla allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Rsjoomla COM Rscomments | 25/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php. | |
| Modificada | Media (4.3) | 1.1% | — | Alkacon Oamp Comments | 26/3/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unspecified vectors. | |
| Modificada | Baja (3.5) | 1.00% | — | Fourkitchens Recent Comments | 25/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Recent Comments module 5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a "custom block title interface." | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 Eluna Page Comments Extension | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Typo3 Eluna Page Comments Extension | 31/12/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.9% | 💥 Exploit | Oocomments | 25/3/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ooComments 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the PathToComment parameter for (1) classes/class_admin.php and (2) classes/class_comments.php. NOTE: the provenance of this information is unknown; the details are obtained solely… |