Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.24% | — | Daleab Membee LoginAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DaleAB Membee Login membees-member-login-widget allows Reflected XSS.This issue affects Membee Login: from n/a through <= 2.3.6. | |
| Aplazada | Alta (8.1) | 0.50% | — | Magic Login Mail OR QR CodeAI | 14/2/2026 | 17/6/2026 | The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing the magic login QR code image with a predictable, static filename (QR_Code.png) in the publicly accessible WordPress uploads directory during the… | |
| Aplazada | Alta (8.8) | 0.35% | 💥 PoC | JAY Login RegisterAI | 8/2/2026 | 17/6/2026 | The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user meta through the 'jay_panel_ajax_update_profile' function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 0.46% | — | JAY Login RegisterAI | 8/2/2026 | 17/6/2026 | The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user meta through the 'jay_login_register_ajax_create_final_user' function. This makes it possible for unauthenticated… | |
| Analizada | Media (6.5) | 0.23% | — | Jaseerkinangattil Microsoft Entra ID SSO Login | 4/2/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Privilege Escalation.This issue affects Microsoft Entra ID SSO Login: from 0.0.0 before 1.0.4. | |
| Aplazada | Media (5.1) | 0.35% | — | Knap Advanced PHP LoginAI | 1/2/2026 | 17/6/2026 | Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious script code in the name parameter. Attackers can exploit the vulnerability to execute arbitrary scripts in users and activity log backend modules, potentially leading to session… | |
| Aplazada | Alta (8.1) | 0.34% | — | Custom Login Page CustomizerAI | 29/1/2026 | 17/6/2026 | The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account | |
| Analizada | Media (4.2) | 0.24% | — | Zyxware Disable Login Page | 28/1/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass.This issue affects Disable Login Page: from 0.0.0 before 1.1.3. | |
| Analizada | Alta (8.1) | 0.16% | — | Innoraft Login Time Restriction | 28/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery.This issue affects Login Time Restriction: from 0.0.0 before 1.0.3. | |
| Aplazada | Alta (8.8) | 0.46% | — | Webdamn User Registration Login SystemAI | 28/1/2026 | 17/6/2026 | WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating email credentials. Attackers can inject the payload '<email>' OR '1'='1' in both username and password fields to gain unauthorized access to the user panel. | |
| Aplazada | Media (4.3) | 0.18% | — | Login Page EditorAI | 24/1/2026 | 17/6/2026 | The Login Page Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing nonce validation on the devotion_loginform_process() AJAX action. This makes it possible for unauthenticated attackers to update the plugin's login page settings via… | |
| Aplazada | Media (4.3) | 0.21% | — | Jahid Hasan Admin Login URL ChangeAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Jahid Hasan Admin login URL Change admin-login-url-change allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin login URL Change: from n/a through <= 1.1.5. | |
| Aplazada | Media (4.3) | 0.26% | — | Sitelock Security WP Hardening Login Security Malware ScansAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans sitelock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SiteLock Security – WP Hardening, Login Security & Malware Scans: from n/a through <= 5.0.2. | |
| Aplazada | Crítica (9.8) | 0.38% | — | Fmeaddons Registration Login With Mobile Phone Number FOR WoocommerceAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registration-login-with-mobile-phone-number allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registration & Login with Mobile Phone Number for WooCommerce: from n/a… | |
| Aplazada | Media (6.4) | 0.27% | — | Marco VAN Wieren Wpo365 LoginAI | 22/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Marco van Wieren WPO365 wpo365-login allows Server Side Request Forgery.This issue affects WPO365: from n/a through <= 40.0. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Registration Login With Mobile Phone NumberAI | 17/1/2026 | 17/6/2026 | The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.1. This is due to the plugin not properly verifying a users identity prior to authenticating them via the fma_lwp_set_session_php_fun() function. This… | |
| Aplazada | Alta (7.5) | 0.23% | — | Marketing Fire LLC Loginwp - PROAI | 5/1/2026 | 7/10/2026 | Missing Authorization vulnerability in Marketing Fire LLC LoginWP - Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LoginWP - Pro: from n/a through 4.0.8.5. | |
| Aplazada | Media (6.5) | 0.23% | — | Marketing Fire LLC Loginwp - PROAI | 5/1/2026 | 7/10/2026 | Missing Authorization vulnerability in Marketing Fire, LLC LoginWP - Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LoginWP - Pro: from n/a through 4.0.8.5. | |
| Aplazada | Media (5.4) | 0.13% | — | Heateor Social LoginAI | 30/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Heateor Support Heateor Social Login heateor-social-login allows Cross Site Request Forgery.This issue affects Heateor Social Login: from n/a through <= 1.1.39. | |
| Aplazada | Media (6.6) | 0.48% | — | Miniorange Wordpress Social Login AND RegisterAI | 30/12/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through <= 7.7.0. | |
| Aplazada | Media (4.3) | 0.12% | — | Pluginops Feather Login PageAI | 22/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page feather-login-page allows Cross Site Request Forgery.This issue affects Feather Login Page: from n/a through <= 1.1.7. | |
| Aplazada | Media (6.5) | 0.29% | — | Awplife Login Page CustomizerAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in A WP Life Login Page Customizer – Customizer Login Page, Admin Page, Custom Design customizer-login-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Page Customizer – Customizer Login Page, Admin Page, Custom Design: from n/a… | |
| Aplazada | Media (6.9) | 0.37% | — | Member Login ScriptAI | 15/12/2025 | 17/6/2026 | Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting Content-Length header parsing. Attackers can send crafted POST requests with smuggled secondary requests to potentially bypass server-side request processing controls. | |
| Aplazada | Crítica (9.8) | 0.75% | 💥 PoC | JAY Login RegisterAI | 13/12/2025 | 17/6/2026 | The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in the 'jay_login_register_process_switch_back' function with the 'jay_login_register_process_switch_back' cookie value. This makes it possible… | |
| Aplazada | Media (5.3) | 0.45% | — | Login Lockdown ProtectionAI | 13/12/2025 | 17/6/2026 | The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and including, 2.14. This is due to $unblock_key key being insufficiently random allowing unauthenticated users, with access to an administrative user email, to generate valid unblock keys for their IP Address.… |