Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

197 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.32%—Codection Import AND Export Users AND Customers8/6/202417/6/2026
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
AplazadaMedia (4.4)0.29%—Webtoffee Import AND Export Users AND CustomersAI15/5/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AplazadaMedia (4.4)0.26%—Codection Import AND Export Users AND CustomersAI15/5/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access…
AplazadaMedia (4.3)0.43%—Webtoffee Import AND Export Users AND CustomersAI4/5/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.4)0.36%—Webtoffee Import Export Wordpress UsersAI24/4/202417/6/2026
Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.3.
AplazadaMedia (4.4)0.37%—Codection Import AND Export Users AND CustomersAI24/4/202417/6/2026
Deserialization of Untrusted Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.2.
AplazadaMedia (5.4)0.20%—Ayecode UserswpAI11/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a before 1.2.6.
ModificadaMedia (6.4)0.45%—Ayecode Userswp9/4/202417/6/2026
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user…
AnalizadaAlta (7.5)0.62%—Icewhale Casaos-userservice1/4/202417/6/2026
Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in version 0.4.8 but that version has not yet…
AplazadaMedia (4.3)0.52%—Webtoffee Import Export Wordpress UsersAI29/3/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.2.
ModificadaMedia (6.1)0.38%—Etoilewebdesign Front END Users26/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Front End Users allows Reflected XSS.This issue affects Front End Users: from n/a before 3.2.25.
AnalizadaAlta (7.5)0.76%—Icewhale Casaos-userservice6/3/202417/6/2026
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS username using the application response. If the username is…
ModificadaAlta (8.8)0.33%—Jonathonkemp Wordpress Users29/1/202417/6/2026
The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
ModificadaMedia (5.4)0.35%—Codection Import AND Export Users AND Customers11/1/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.24.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
ModificadaAlta (7.2)0.80%—Codection Import AND Export Users AND Customers11/1/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary…
ModificadaAlta (7.2)1.4%—Webtoffee Import Export Wordpress Users11/1/202417/6/2026
The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for authenticated attackers with shop manager-level capabilities or above,…
ModificadaMedia (5.3)0.43%—Sumanbhattarai Send Users Email5/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Suman Bhattarai Send Users Email.This issue affects Send Users Email: from n/a through 1.4.3.
ModificadaAlta (7.5)0.45%—Smackcoders Export ALL Posts, Products, Orders, Refunds & Users21/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
ModificadaMedia (4.8)0.39%—Zealousweb Track Geolocation OF Users Using Contact Form 715/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZealousWeb Track Geolocation Of Users Using Contact Form 7 allows Stored XSS.This issue affects Track Geolocation Of Users Using Contact Form 7: from n/a through 2.0.
ModificadaAlta (7.5)0.53%—Smackcoders Export ALL Posts, Products, Orders, Refunds & Users30/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
ModificadaAlta (8.8)0.82%—Patrickrobrecht Posts AND Users Stats7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in Patrick Robrecht Posts and Users Stats.This issue affects Posts and Users Stats: from n/a through 1.1.3.
ModificadaAlta (8.8)0.82%—Kaushikkalathiya Export Users Data7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in Kaushik Kalathiya Export Users Data CSV.This issue affects Export Users Data CSV: from n/a through 2.1.
ModificadaAlta (8.8)0.80%—Narolainfotech Export Users Data Distinct7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in Narola Infotech Solutions LLP Export Users Data Distinct.This issue affects Export Users Data Distinct: from n/a through 1.3.
ModificadaAlta (8.8)0.78%—Anmari AMR Users7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in anmari amr users.This issue affects amr users: from n/a through 4.59.4.
ModificadaAlta (8.8)0.68%—Ayecode Userswp7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.
Orbitaley — Vulnerabilidades