Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 1.7% | 💥 PoC | Backdropcms Backdrop CMS | 3/2/2025 | 17/6/2026 | An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administrator attempts to… | |
| Aplazada | Crítica (9.6) | 0.64% | — | Dumb DropAI | 31/1/2025 | 17/6/2026 | Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrite arbitrary system files. As the container runs as root by default, there is no limit to what can be overwritten. With this, it's possible to inject malicious payloads… | |
| Analizada | Crítica (9.1) | 0.33% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 31/1/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.4) | 0.31% | — | Post AND Page Builder BY Boldgrid - Visual Drag AND Drop Editor | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Stored XSS.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.5. | |
| Aplazada | Media (6.4) | 0.40% | — | PDF FOR Wpforms Drag AND Drop Template BuilderAI | 15/1/2025 | 17/6/2026 | The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yeepdf_dotab shortcode in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.28% | — | Yonisink Sinking DropdownsAI | 31/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in yonisink Sinking Dropdowns sinking-dropdowns allows Privilege Escalation.This issue affects Sinking Dropdowns: from n/a through <= 1.25. | |
| Aplazada | Media (6.4) | 0.35% | — | Geodatasource Country Region DropdownAI | 14/12/2024 | 17/6/2026 | The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.53% | — | Villatheme ALD Dropshipping AND Fulfillment FOR Aliexpress AND WoocommerceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme(villatheme.com) ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce: from n/a through 1.0.21. | |
| Aplazada | Media (6.5) | 0.53% | — | Sharkdropship Woo-aliexpress-dropshippingAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Marc dooder Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy woo-aliexpress-dropshipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through <=… | |
| Aplazada | Media (6.5) | 0.41% | — | Sharkdropship FOR Aliexpress Dropship AND AffiliateAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in wooproductimporter Sharkdropship for AliExpress Dropship and Affiliate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharkdropship for AliExpress Dropship and Affiliate: from n/a through 2.2.3. | |
| Aplazada | Media (6.1) | 0.29% | — | Wordpress Drag Drop Builder Human Face Detector PRE Built Templates Spam Protection User Email Notifications MoreAI | 7/12/2024 | 17/6/2026 | The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.19 due to insufficient input sanitization and output escaping.… | |
| Aplazada | Alta (8.2) | 0.19% | — | Dropbox SignAI | 5/12/2024 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all… | |
| Analizada | Media (6.1) | 0.29% | — | Backdropcms Backdrop CMS | 29/11/2024 | 17/6/2026 | Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format. | |
| Aplazada | Media (6.5) | 0.30% | — | Gopiplus Drop IN Image Slideshow GalleryAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus drop in image slideshow gallery drop-in-image-slideshow-gallery allows DOM-Based XSS.This issue affects drop in image slideshow gallery: from n/a through <= 12.0. | |
| Aplazada | Media (6.3) | 0.61% | — | Drop Shadow BoxesAI | 16/11/2024 | 17/6/2026 | The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.26% | — | Dropshipping Guru Ali2woo LiteAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Dropshipping Guru Ali2Woo Lite Exploiting Incorrectly Configured Access Control Security Levels, Stored XSS.This issue affects Ali2Woo Lite: from n/a through 3.3.5. | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Redwanhilali WP Dropbox Dropins | 20/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in redhopit WP Dropbox Dropins wp-dropbox-dropins allows Upload a Web Shell to a Web Server.This issue affects WP Dropbox Dropins: from n/a through <= 1.0. | |
| Modificada | Crítica (9.8) | 0.47% | — | Madirisalmanaashish Adding Drop Down Roles IN Registration | 17/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in madiriaashish Adding drop down roles in registration user-drop-down-roles-in-registration allows Privilege Escalation.This issue affects Adding drop down roles in registration: from n/a through <= 1.1. | |
| Analizada | Media (5.3) | 0.58% | — | Rems Drag AND Drop Image Upload | 15/10/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (5.4) | 0.34% | — | Gcsdesign WP Category Dropdown | 25/9/2024 | 17/6/2026 | The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Media (6.1) | 0.27% | — | Ali2woo Aliexpress Dropshipping With Alinext | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ali2Woo Team Ali2Woo Lite allows Reflected XSS.This issue affects Ali2Woo Lite: from n/a through 3.3.5. | |
| Modificada | Media (4.8) | 0.32% | — | Backdropcms Backdrop | 22/7/2024 | 17/6/2026 | Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission. | |
| Analizada | Alta (8.8) | 0.21% | — | Ali2woo Aliexpress Dropshipping With Alinext | 21/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ali2Woo Ali2Woo Lite.This issue affects Ali2Woo Lite: from n/a through 3.3.5. | |
| Aplazada | Alta (7.3) | 11% | — | Servmask All-in-one WP Migration BOX ExtensionAIServmask All-in-one WP Migration Onedrive ExtensionAIServmask All-in-one WP Migration Dropbox ExtensionAIServmask All-in-one WP Migration Google Drive ExtensionAI | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP Migration Google Drive Extension.This issue affects All-in-One WP Migration Box Extension: from n/a… | |
| Modificada | Media (6.3) | 0.33% | — | Ali2woo Aliexpress Dropshipping With Alinext | 19/6/2024 | 17/6/2026 | The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ImportAjaxController.php file in all versions up to, and including, 3.3.6. This makes it possible for authenticated attackers, with subscriber-level… |