Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.24% | — | Danny Vink User Profile Meta ManagerAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows Privilege Escalation.This issue affects User Profile Meta Manager: from n/a through <= 1.02. | |
| Aplazada | Media (4.3) | 0.23% | — | Metagauss ProfilegridAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid : from n/a through <= 5.9.5.1. | |
| Analizada | Media (4.8) | 0.34% | — | Cozmoslabs Profile Builder | 15/5/2025 | 17/6/2026 | The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks. | |
| Analizada | Media (5.4) | 0.31% | — | Wpproking Profilepro | 15/5/2025 | 17/6/2026 | The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks | |
| Aplazada | Baja (2.1) | 0.47% | — | Julmud PhpdvdprofilerAIInvelos DvdprofilerAI | 12/5/2025 | 17/6/2026 | julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web their DVD collections maintained with Invelos's DVDProfiler software. Starting in v_20230807 and prior to v_20250511, cross-site scripting in the search function. v_20250511 contains a patch for the… | |
| Aplazada | Media (5.3) | 0.38% | — | Peprodev Ultimate Profile SolutionsAI | 7/5/2025 | 17/6/2026 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its publicly exposed reset-password endpoint. The plugin looks up the 'valid_email' value based solely on a supplied username parameter, without verifying that the requester is associated with that user… | |
| Aplazada | Alta (8.2) | 0.45% | — | Peprodev Ultimate Profile SolutionsAI | 7/5/2025 | 17/6/2026 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handel_ajax_req() function in versions 1.9.1 to 7.5.2. This makes it possible for unauthenticated attackers to update arbitrary user's metadata which can be leveraged… | |
| Aplazada | Crítica (9.8) | 0.63% | — | Peprodev Ultimate Profile SolutionsAI | 7/5/2025 | 17/6/2026 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to 7.5.2. This is due to handel_ajax_req() function not having proper restrictions on the change_user_meta functionality that makes it possible to set a OTP code and subsequently log in with that OTP… | |
| Aplazada | Alta (8.5) | 0.34% | — | Metagauss ProfilegridAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.4.8. | |
| Aplazada | Media (6.4) | 0.31% | — | Codespress User Profile BuilderAI | 16/4/2025 | 17/6/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Alta (8.8) | 0.39% | — | John James Jacoby WP User ProfilesAI | 10/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Escalation.This issue affects WP User Profiles: from n/a through <= 2.6.2. | |
| Aplazada | Media (5.3) | 0.50% | — | Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI | 1/4/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Retrieve Embedded Sensitive Data.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through… | |
| Analizada | Media (5.3) | 0.45% | — | Profile Private Project Profile Private | 31/3/2025 | 17/6/2026 | Vulnerability in Drupal Profile Private.This issue affects Profile Private: *.*. | |
| Aplazada | Media (4.3) | 0.28% | — | Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a… | |
| Analizada | Media (4.3) | 0.29% | — | Metagauss Profilegrid | 22/3/2025 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4. This makes it possible for… | |
| Analizada | Alta (8.8) | 0.63% | — | Metagauss Profilegrid | 22/3/2025 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted input in the get_user_meta_fields_html function. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Analizada | Media (6.5) | 0.38% | — | Metagauss Profilegrid | 22/3/2025 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and including, 5.9.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Alta (8.8) | 0.70% | — | Metagauss ProfilegridAI | 3/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Object Injection.This issue affects ProfileGrid : from n/a through <= 5.9.4.3. | |
| Aplazada | Media (5.4) | 0.15% | — | Forge12 Interactive Gmbh F12-profilerAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Forge12 Interactive GmbH F12-Profiler f12-profiler allows Cross Site Request Forgery.This issue affects F12-Profiler: from n/a through <= 1.3.9. | |
| Aplazada | Media (6.5) | 0.27% | — | Pankaj Mondal Profile Widget NinjaAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pankaj Mondal Profile Widget Ninja profile-widget-ninja allows DOM-Based XSS.This issue affects Profile Widget Ninja: from n/a through <= 4.3. | |
| Analizada | Media (4.3) | 0.29% | — | Metagauss Profilegrid | 18/2/2025 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Analizada | Media (5.4) | 0.36% | — | Metagauss Profilegrid | 18/2/2025 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web… | |
| Analizada | Baja (3.5) | 0.32% | — | Properfraction Profilepress | 13/2/2025 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html… | |
| Analizada | Media (4.8) | 0.31% | — | Properfraction Profilepress | 13/2/2025 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html… | |
| Analizada | Media (4.8) | 0.36% | — | Properfraction Profilepress | 13/2/2025 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html… |