Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
2432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.49% | — | Plugin-planet Simple Ajax ChatAI | 11/9/2026 | 11/9/2026 | The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (7.5) | 0.30% | — | Gingerplugins Sticky Chat WidgetAI | 11/9/2026 | 11/9/2026 | The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to… | |
| Pendiente de análisis | Media (4.4) | 0.12% | — | Gstreamer Gst-plugins-goodAI | 11/9/2026 | 16/9/2026 | A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes,… | |
| Aplazada | Alta (8.8) | 2.9% | — | Newfold WP Module DataAINewfold WP Plugin Crazy DomainsAINewfold WP Plugin WEBAINewfold WP Plugin HostgatorAI+1 | 9/9/2026 | 9/9/2026 | Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request —… | |
| Aplazada | Media (5.9) | 0.23% | — | Paymentplugins Payment Plugins FOR Paypal WoocommerceAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then charge or delete it. Exploitation requires… | |
| Aplazada | Media (5.3) | 0.34% | — | Payment Plugins FOR Paypal WoocommerceAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the secret that gates access to any order and, through it, that customer's billing and… | |
| Aplazada | Media (5.3) | 0.34% | — | Paymentpluginsforstripe Payment Plugins FOR StripeAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by… | |
| Pendiente de análisis | Baja (2.1) | 0.10% | — | Android WatchAIAndroid Watch PluginAI | 9/9/2026 | 10/9/2026 | Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information. | |
| Aplazada | Media (5.4) | 0.21% | — | Booking-wp-plugin BooklyAI | 8/9/2026 | 8/9/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (7.1) | 0.25% | — | 100plugins Open User MAPAI | 8/9/2026 | 8/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions. | |
| Aplazada | Alta (7.2) | 0.27% | — | Wpplugins Hide MY WP GhostAI | 8/9/2026 | 8/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09. | |
| Aplazada | Alta (7.5) | 0.21% | — | Verygoodplugins WP FusionAI | 7/9/2026 | 8/9/2026 | The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.7) | 0.39% | — | Getgrav Grav-plugin-apiAI | 5/9/2026 | 8/9/2026 | grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. A non-super user manager with api.access and api.users.write permissions can… | |
| Aplazada | Alta (8.7) | 0.36% | — | Getgrav Grav-plugin-apiAI | 5/9/2026 | 8/9/2026 | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control. | |
| Aplazada | Media (6.9) | 0.56% | — | Getgrav Grav Form PluginAI | 5/9/2026 | 18/9/2026 | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Pickplugins ComboblocksAI | 5/9/2026 | 8/9/2026 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress,… | |
| Aplazada | Media (6.4) | 0.42% | — | Fooplugins FoogalleryAI | 5/9/2026 | 8/9/2026 | The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Media (6.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 5/9/2026 | 8/9/2026 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who… | |
| Aplazada | Crítica (9.3) | 0.36% | — | Getgrav Grav-plugin-formAI | 4/9/2026 | 8/9/2026 | The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous attacker can place their v3 token under the v2 field name… | |
| Aplazada | Media (5.1) | 0.24% | — | Getgrav Grav-plugin-admin2AI | 4/9/2026 | 8/9/2026 | Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation templates before parsing the result as markdown. Grav's server-side username… | |
| Aplazada | Media (5.3) | 0.29% | — | Kings Plugins MarketkingAI | 4/9/2026 | 7/9/2026 | Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: from n/a through 2.1.60. | |
| Aplazada | Alta (7.1) | 0.25% | — | Fullworksplugins Quick Event ManagerAI | 3/9/2026 | 4/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fullworksplugins Quick Event ManagerAI | 3/9/2026 | 5/9/2026 | Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Jenkins Parameterized Remote Trigger PluginAI | 2/9/2026 | 3/9/2026 | Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Pendiente de análisis | Alta (7.4) | 1.2% | — | Jenkins Tics PluginAI | 2/9/2026 | 3/9/2026 | OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build. |