Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

228 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.36%—Heateor Fancy Comments30/3/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Team Heateor Fancy Comments WordPress plugin <= 1.2.10 versions.
ModificadaMedia (4.8)0.39%—Wp-commentnavi Project Wp-commentnavi23/3/202317/6/2026
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Lester 'GaMerZ' Chan WP-CommentNavi plugin <= 1.12.1 versions.
ModificadaMedia (5.4)0.64%—Markjaquith Subscribe TO Comments5/3/202316/6/2026
A vulnerability, which was classified as problematic, was found in Subscribe to Comments Plugin up to 2.0.7 on WordPress. This affects an unknown part of the file subscribe-to-comments.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.8 is…
ModificadaMedia (6.1)0.90%💥 ExploitAppjetty Show ALL Comments16/1/202317/6/2026
The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.
ModificadaMedia (4.8)0.56%—ADD Comments Project ADD Comments5/12/202217/6/2026
The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (4.8)0.59%—Webgilde Advanced Comment Form10/10/202217/6/2026
The Advanced Comment Form WordPress plugin before 1.2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (4.8)0.50%—Comment Guestbook Project Comment Guestbook30/9/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress.
ModificadaMedia (6.1)0.55%—Prestashop Productcomments2/9/202217/6/2026
This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an administrator's cookie. The issue is fixed in version 5.0.2.
ModificadaMedia (6.5)0.66%—Stop Spam Comments Project Stop Spam Comments29/8/202217/6/2026
The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment section, allowing threat authors to easily collect the value and add it to the request.
ModificadaMedia (4.8)0.61%—Najeebmedia Wordpress Comments Fields8/8/202217/6/2026
The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (4.3)0.43%—Comment License Project Comment License11/7/202217/6/2026
The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (6.1)2.9%—Turn OFF ALL Comments Project Turn OFF ALL Comments23/5/202217/6/2026
The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (5.4)0.39%—Wpkube Subscribe TO Comments Reloaded29/4/202217/6/2026
Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key, reset all options, change notifications…
ModificadaMedia (4.8)0.60%—Wpdevart Social Comments25/4/202217/6/2026
The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (4.8)0.60%—Good-bad-comments Project Good-bad-comments18/4/202217/6/2026
The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaBaja (3.1)0.49%—Bologer Anycomment21/2/202217/6/2026
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users
ModificadaAlta (8.8)0.65%—Bologer Anycomment21/2/202217/6/2026
The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (6.1)2.2%💥 ExploitBologer Anycomment17/1/202217/6/2026
The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.
ModificadaMedia (5.4)0.57%—Comment Engine PRO Project Comment Engine PRO10/12/202117/6/2026
Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), could be exploited by users with Editor or higher role.
ModificadaMedia (6.5)0.62%—Delete ALL Comments Easily Project Delete ALL Comments Easily1/11/202117/6/2026
The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.
ModificadaMedia (6.1)0.41%—Jquery-reply-to-comment Project Jquery-reply-to-comment25/10/202117/6/2026
The jQuery Reply to Comment WordPress plugin through 1.31 does not have any CSRF check when saving its settings, nor sanitise or escape its 'Quote String' and 'Reply String' settings before outputting them in Comments, leading to a Stored Cross-Site Scripting issue.
ModificadaMedia (4.3)0.49%—Quantumcloud Comment Link Remove AND Other Comment Tools13/9/202117/6/2026
The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments
ModificadaMedia (6.1)0.90%—Sw-guide Edit Comments XT10/9/202117/6/2026
The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.
ModificadaAlta (7.5)0.89%—Onyaktech Comments PRO Project Onyaktech Comments PRO7/9/202117/6/2026
An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the installer, decompile it, and discover a hardcoded IV used to encrypt the username and userid in the comment POST request. Additionally, the attacker can decrypt the encrypted encryption key (sent as a…
Orbitaley — Vulnerabilidades