Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.36% | — | Heateor Fancy Comments | 30/3/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Team Heateor Fancy Comments WordPress plugin <= 1.2.10 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Wp-commentnavi Project Wp-commentnavi | 23/3/2023 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Lester 'GaMerZ' Chan WP-CommentNavi plugin <= 1.12.1 versions. | |
| Modificada | Media (5.4) | 0.64% | — | Markjaquith Subscribe TO Comments | 5/3/2023 | 16/6/2026 | A vulnerability, which was classified as problematic, was found in Subscribe to Comments Plugin up to 2.0.7 on WordPress. This affects an unknown part of the file subscribe-to-comments.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.8 is… | |
| Modificada | Media (6.1) | 0.90% | 💥 Exploit | Appjetty Show ALL Comments | 16/1/2023 | 17/6/2026 | The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin. | |
| Modificada | Media (4.8) | 0.56% | — | ADD Comments Project ADD Comments | 5/12/2022 | 17/6/2026 | The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.59% | — | Webgilde Advanced Comment Form | 10/10/2022 | 17/6/2026 | The Advanced Comment Form WordPress plugin before 1.2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.8) | 0.50% | — | Comment Guestbook Project Comment Guestbook | 30/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress. | |
| Modificada | Media (6.1) | 0.55% | — | Prestashop Productcomments | 2/9/2022 | 17/6/2026 | This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an administrator's cookie. The issue is fixed in version 5.0.2. | |
| Modificada | Media (6.5) | 0.66% | — | Stop Spam Comments Project Stop Spam Comments | 29/8/2022 | 17/6/2026 | The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment section, allowing threat authors to easily collect the value and add it to the request. | |
| Modificada | Media (4.8) | 0.61% | — | Najeebmedia Wordpress Comments Fields | 8/8/2022 | 17/6/2026 | The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (4.3) | 0.43% | — | Comment License Project Comment License | 11/7/2022 | 17/6/2026 | The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (6.1) | 2.9% | — | Turn OFF ALL Comments Project Turn OFF ALL Comments | 23/5/2022 | 17/6/2026 | The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.39% | — | Wpkube Subscribe TO Comments Reloaded | 29/4/2022 | 17/6/2026 | Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key, reset all options, change notifications… | |
| Modificada | Media (4.8) | 0.60% | — | Wpdevart Social Comments | 25/4/2022 | 17/6/2026 | The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (4.8) | 0.60% | — | Good-bad-comments Project Good-bad-comments | 18/4/2022 | 17/6/2026 | The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Baja (3.1) | 0.49% | — | Bologer Anycomment | 21/2/2022 | 17/6/2026 | The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users | |
| Modificada | Alta (8.8) | 0.65% | — | Bologer Anycomment | 21/2/2022 | 17/6/2026 | The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Bologer Anycomment | 17/1/2022 | 17/6/2026 | The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature. | |
| Modificada | Media (5.4) | 0.57% | — | Comment Engine PRO Project Comment Engine PRO | 10/12/2021 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), could be exploited by users with Editor or higher role. | |
| Modificada | Media (6.5) | 0.62% | — | Delete ALL Comments Easily Project Delete ALL Comments Easily | 1/11/2021 | 17/6/2026 | The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog. | |
| Modificada | Media (6.1) | 0.41% | — | Jquery-reply-to-comment Project Jquery-reply-to-comment | 25/10/2021 | 17/6/2026 | The jQuery Reply to Comment WordPress plugin through 1.31 does not have any CSRF check when saving its settings, nor sanitise or escape its 'Quote String' and 'Reply String' settings before outputting them in Comments, leading to a Stored Cross-Site Scripting issue. | |
| Modificada | Media (4.3) | 0.49% | — | Quantumcloud Comment Link Remove AND Other Comment Tools | 13/9/2021 | 17/6/2026 | The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments | |
| Modificada | Media (6.1) | 0.90% | — | Sw-guide Edit Comments XT | 10/9/2021 | 17/6/2026 | The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0. | |
| Modificada | Alta (7.5) | 0.89% | — | Onyaktech Comments PRO Project Onyaktech Comments PRO | 7/9/2021 | 17/6/2026 | An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the installer, decompile it, and discover a hardcoded IV used to encrypt the username and userid in the comment POST request. Additionally, the attacker can decrypt the encrypted encryption key (sent as a… |