Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.23% | — | Shaharia Azam Auto Post After Image UploadAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Shaharia Azam Auto Post After Image Upload auto-post-after-image-upload allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Post After Image Upload: from n/a through <= 1.6. | |
| Aplazada | Alta (8.8) | 0.89% | — | Wpzone Inline Image Upload FOR BbpressAI | 29/3/2025 | 17/6/2026 | The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the file uploading functionality in all versions up to, and including, 1.1.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Analizada | Alta (8.8) | 0.59% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 28/3/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted input from the 'dnd_upload_cf7_upload' function. This makes it possible for attackers to inject a PHP Object through a PHAR… | |
| Analizada | Alta (8.8) | 1.1% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 28/3/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'dnd_remove_uploaded_files' function in all versions up to, and including, 1.3.8.7. This makes it possible for unauthenticated attackers to add… | |
| Analizada | Media (4.8) | 0.26% | — | WP SVG Upload Project WP SVG Upload | 26/3/2025 | 17/6/2026 | The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks. | |
| Aplazada | Media (4.3) | 0.18% | — | Link OSS UploadAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Link OSS Upload oss-upload allows Cross Site Request Forgery.This issue affects OSS Upload: from n/a through <= 4.8.9. | |
| Aplazada | Media (5.9) | 0.37% | — | Cristian Sarov Upload Quota PER UserAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristian Sarov Upload Quota per User upload-quota-per-user allows Stored XSS.This issue affects Upload Quota per User: from n/a through <= 1.3. | |
| Modificada | Media (6.4) | 0.29% | — | Apprhyme URL Media Uploader | 28/2/2025 | 17/6/2026 | The URL Media Uploader plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.0 via the 'url_media_uploader_url_upload' action. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrary locations… | |
| Analizada | Media (4.3) | 0.17% | — | Iptanus Wordpress File Upload | 25/2/2025 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the 'wfu_file_details' function. This makes it possible for unauthenticated attackers to modify user data details associated… | |
| Modificada | Alta (7.5) | 0.51% | — | Imaginate-solutions File Uploads Addon FOR Woocommerce | 18/2/2025 | 17/6/2026 | The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory… | |
| Aplazada | Media (6.5) | 0.30% | — | Rpldy UploaderAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Aplazada | Media (5.4) | 0.29% | — | Wpdeveloper Document Block Upload Embed DocsAI | 4/2/2025 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Document Block – Upload & Embed Docs document.This issue affects Document Block – Upload & Embed Docs: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.1) | 0.28% | — | Pepro DEV Group Pepro Bacs Receipt Upload FOR WoocommerceAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev WooCommerce Receipt Uploader pepro-bacs-receipt-upload-for-woocommerce allows Reflected XSS.This issue affects PeproDev WooCommerce Receipt Uploader: from n/a through <= 2.6.9. | |
| Analizada | Crítica (9.1) | 0.33% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 31/1/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it possible for unauthenticated attackers to… | |
| Analizada | Crítica (9.1) | 0.53% | — | Ivanm WP Image Uploader | 30/1/2025 | 17/6/2026 | The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploader_main_function() function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server,… | |
| Analizada | Alta (8.1) | 0.24% | — | Ivanm WP Image Uploader | 30/1/2025 | 17/6/2026 | The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the gky_image_uploader_main_function() function. This makes it possible for unauthenticated attackers to delete arbitrary files via… | |
| Aplazada | Media (6.1) | 0.29% | — | Ivanm WP Image UploaderAI | 30/1/2025 | 17/6/2026 | The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Crítica (9) | 0.53% | — | Sh1zen Multi Uploader FOR Gravity FormsAIGravityforms Gravity FormsAI | 22/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-uploader allows Upload a Web Shell to a Web Server.This issue affects Multi Uploader for Gravity Forms: from n/a through <= 1.1.3. | |
| Aplazada | Media (6.4) | 0.41% | — | Picture Gallery Frontend Image Uploads Ajax Photo ListAI | 18/1/2025 | 17/6/2026 | The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videowhisper_picture_upload_guest shortcode in all versions up to, and including, 1.5.22 due to insufficient input sanitization and output escaping on user supplied… | |
| Modificada | Alta (7.5) | 1.1% | — | Iptanus Wordpress File Upload | 8/1/2025 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory. | |
| Modificada | Crítica (9.8) | 1.5% | 💥 PoC | Iptanus Wordpress File Upload | 8/1/2025 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server. | |
| Modificada | Crítica (9.8) | 4.5% | 💥 PoC | Iptanus Wordpress File Upload | 8/1/2025 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined… | |
| Analizada | Media (4.3) | 0.35% | — | Iptanus Wordpress File Upload | 7/1/2025 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.26% | — | Kurt Payne Upload ScannerAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kurt Payne Upload Scanner upload-scanner allows Reflected XSS.This issue affects Upload Scanner: from n/a through <= 1.2. | |
| Aplazada | Media (6.4) | 0.40% | — | Support SVG Upload SVG Files IN Wordpress Without HassleAI | 26/11/2024 | 17/6/2026 | The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… |