Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
157 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.20% | — | Saleswonder Builder FOR Woocommerce Reviews Shortcodes ReviewshortAI | 19/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias Builder for WooCommerce reviews shortcodes – ReviewShort woo-product-reviews-shortcode.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through <= 1.01.3. | |
| Aplazada | Media (5.9) | 0.32% | — | Geminilabs Site ReviewsAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gemini Labs Site Reviews site-reviews.This issue affects Site Reviews: from n/a through <= 6.11.6. | |
| Modificada | Media (6.1) | 0.38% | — | Etoilewebdesign Ultimate Reviews | 15/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8. | |
| Aplazada | Media (6.4) | 0.55% | — | Geminilabs Site ReviewsAI | 13/3/2024 | 17/6/2026 | The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary… | |
| Modificada | Media (5.3) | 0.41% | — | Cusrev Customer Reviews FOR Woocommerce | 29/2/2024 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to submit reviews with arbitrary email… | |
| Modificada | Media (4.3) | 0.34% | — | Cusrev Customer Reviews FOR Woocommerce | 28/2/2024 | 17/6/2026 | Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1. | |
| Modificada | Media (5.4) | 0.61% | — | Richplugins Plugin FOR Google Reviews | 5/2/2024 | 17/6/2026 | This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'place_id' attribute. This makes it possible for authenticated attackers with contributor-level and above… | |
| Modificada | Media (5.4) | 0.53% | — | Cusrev Customer Reviews FOR Woocommerce | 16/1/2024 | 17/6/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 1.1% | — | Cusrev Customer Reviews FOR Woocommerce | 11/1/2024 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to… | |
| Modificada | Alta (8.8) | 0.26% | — | Reviewsignal Wpperformancetester | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kevin Ohashi WPPerformanceTester.This issue affects WPPerformanceTester: from n/a through 2.0.0. | |
| Modificada | Media (4.3) | 0.52% | — | Gowebsolutions WP Customer Reviews | 22/11/2023 | 17/6/2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.6.6 via the ajax_enabled_posts function. This can allow authenticated attackers to extract sensitive data such as post titles and slugs, including those of protected and trashed posts and… | |
| Modificada | Crítica (9.8) | 0.70% | — | Geminilabs Site Reviews | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Paul Ryley Site Reviews.This issue affects Site Reviews: from n/a through 6.2.0. | |
| Modificada | Crítica (9.8) | 0.70% | — | Webtoffee Product Reviews Import Export FOR Woocommerce | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee Product Reviews Import Export for WooCommerce.This issue affects Product Reviews Import Export for WooCommerce: from n/a through 1.4.8. | |
| Modificada | Media (4.8) | 0.35% | — | Gowebsolutions WP Customer Reviews | 20/10/2023 | 17/6/2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (4.3) | 0.20% | — | Trustedindex Widgets FOR Google Reviews | 18/10/2023 | 17/6/2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.9. This is due to missing or incorrect nonce validation within setup_no_reg_header.php. This makes it possible for unauthenticated attackers to reset plugin settings and remove reviews… | |
| Modificada | Media (4.3) | 0.56% | — | Codesupply Absolute Reviews | 12/7/2023 | 17/6/2026 | The Absolute Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on the metabox_review_save() function. This makes it possible for unauthenticated attackers to save meta tags via a forged request granted… | |
| Modificada | Media (5.4) | 0.41% | — | Geminilabs Site Reviews | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. | |
| Modificada | Media (5.4) | 0.40% | — | Geminilabs Site Reviews | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. | |
| Modificada | Crítica (9.8) | 1.6% | — | Etoilewebdesign Ultimate Reviews | 7/6/2023 | 17/6/2026 | The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. | |
| Modificada | Media (4.8) | 0.37% | — | Skeepers Verified Reviews (avis Verifies) | 16/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NetReviews SAS Verified Reviews (Avis Vérifiés) plugin <= 2.3.13 versions. | |
| Modificada | Media (4.8) | 0.50% | — | Geminilabs Site Reviews | 2/5/2023 | 17/6/2026 | The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.4) | 0.44% | — | Ms-reviews Project Ms-reviews | 24/4/2023 | 17/6/2026 | The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.63% | — | Richplugins Plugin FOR Google Reviews | 15/3/2023 | 17/6/2026 | SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions. | |
| Modificada | Alta (8.8) | 0.90% | — | Prestashop Advanced Reviews | 14/3/2023 | 17/6/2026 | PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection. | |
| Modificada | Alta (8.8) | 1.1% | — | Cusrev Customer Reviews FOR Woocommerce | 13/2/2023 | 17/6/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also… |