Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

615 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.25%—Joomunited WP File Download21/6/202517/6/2026
The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
AplazadaAlta (7.1)0.13%—R-win Wp-downloadcounterAI20/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in r-win WP-DownloadCounter wp-downloadcounter allows Stored XSS.This issue affects WP-DownloadCounter: from n/a through <= 1.01.
AplazadaMedia (5.3)0.35%—Dfactory Download AttachmentsAI20/6/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Attachments: from n/a through <= 1.3.1.
AnalizadaMedia (5.4)0.25%—W3eden Download Manager19/6/202517/6/2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AnalizadaMedia (5.5)0.61%—Sourcecodester Downloading Client Database Management System17/6/202517/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_customer_create_order.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The…
AnalizadaAlta (7.2)0.94%—Wp-downloadmanager Project Wp-downloadmanager11/6/202517/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary…
AnalizadaMedia (4.9)0.42%—Wp-downloadmanager Project Wp-downloadmanager11/6/202517/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storing downloads. This makes it possible for authenticated attackers, with Administrator-level access…
AnalizadaMedia (5.4)0.34%—Awesomemotive Easy Digital Downloads29/5/202517/6/2026
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This…
AplazadaAlta (8.6)0.35%—Reint DownloadmanagerAITypo3AI21/5/202517/6/2026
The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.
AnalizadaMedia (6.1)0.26%—Sfarbota Download Html Tinymce Button15/5/202517/6/2026
The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AnalizadaMedia (6.1)0.32%—Urbanbase Z-downloads15/5/202517/6/2026
The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks when accessing share URLs.
AnalizadaAlta (7.2)0.67%—Urbanbase Z-downloads15/5/202517/6/2026
The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
AnalizadaCrítica (9.1)1.8%💥 ExploitUrbanbase Z-downloads15/5/202517/6/2026
The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.
AnalizadaMedia (4.8)0.35%—W3eden Download Manager15/5/202517/6/2026
The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
AnalizadaMedia (6.5)0.51%—Wpbookingcalendar Secure Downloads15/5/202517/6/2026
The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php.
AnalizadaMedia (5.4)0.31%—Freebiesdownload PVN Auth Popup15/5/202517/6/2026
The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
AnalizadaMedia (4.8)0.32%—Freebiesdownload PVN Auth Popup15/5/202517/6/2026
The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaMedia (5.4)0.18%—Westerndeal Easy Digital Downloads Google Sheet ConnectorEDD Gsheetconnector15/5/202517/6/2026
The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
AplazadaAlta (7.5)0.80%—Wpchill Download MonitorAI7/5/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects Download Monitor: from n/a through <= 5.0.22.
AplazadaMedia (4.3)0.26%—M.code Media Library DownloaderAI24/4/202517/6/2026
Missing Authorization vulnerability in M.Code Media Library Downloader media-library-downloader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media Library Downloader: from n/a through <= 1.3.1.
ModificadaMedia (5.4)0.22%—Plugin-planet Simple Download Counter22/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter simple-download-counter allows Stored XSS.This issue affects Simple Download Counter: from n/a through <= 2.2.
AplazadaAlta (8.8)1.1%—Download ManagerAI19/4/202517/6/2026
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the…
AplazadaMedia (5.4)0.37%—Download ManagerAI18/4/202517/6/2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…
AplazadaMedia (6.5)0.36%—Maennchen1 M1 DownloadlistAI8/4/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadList m1downloadlist allows Retrieve Embedded Sensitive Data.This issue affects m1.DownloadList: from n/a through <= 0.24.
AplazadaAlta (7.1)0.14%—Infoway Ebook DownloaderAI1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Infoway LLC Ebook Downloader ebook-downloader allows Cross Site Request Forgery.This issue affects Ebook Downloader: from n/a through <= 1.0.