Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.25% | — | Joomunited WP File Download | 21/6/2025 | 17/6/2026 | The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Aplazada | Alta (7.1) | 0.13% | — | R-win Wp-downloadcounterAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in r-win WP-DownloadCounter wp-downloadcounter allows Stored XSS.This issue affects WP-DownloadCounter: from n/a through <= 1.01. | |
| Aplazada | Media (5.3) | 0.35% | — | Dfactory Download AttachmentsAI | 20/6/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Attachments: from n/a through <= 1.3.1. | |
| Analizada | Media (5.4) | 0.25% | — | W3eden Download Manager | 19/6/2025 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Media (5.5) | 0.61% | — | Sourcecodester Downloading Client Database Management System | 17/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_customer_create_order.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Alta (7.2) | 0.94% | — | Wp-downloadmanager Project Wp-downloadmanager | 11/6/2025 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary… | |
| Analizada | Media (4.9) | 0.42% | — | Wp-downloadmanager Project Wp-downloadmanager | 11/6/2025 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storing downloads. This makes it possible for authenticated attackers, with Administrator-level access… | |
| Analizada | Media (5.4) | 0.34% | — | Awesomemotive Easy Digital Downloads | 29/5/2025 | 17/6/2026 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Alta (8.6) | 0.35% | — | Reint DownloadmanagerAITypo3AI | 21/5/2025 | 17/6/2026 | The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference. | |
| Analizada | Media (6.1) | 0.26% | — | Sfarbota Download Html Tinymce Button | 15/5/2025 | 17/6/2026 | The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (6.1) | 0.32% | — | Urbanbase Z-downloads | 15/5/2025 | 17/6/2026 | The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks when accessing share URLs. | |
| Analizada | Alta (7.2) | 0.67% | — | Urbanbase Z-downloads | 15/5/2025 | 17/6/2026 | The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup) | |
| Analizada | Crítica (9.1) | 1.8% | 💥 Exploit | Urbanbase Z-downloads | 15/5/2025 | 17/6/2026 | The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript. | |
| Analizada | Media (4.8) | 0.35% | — | W3eden Download Manager | 15/5/2025 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Analizada | Media (6.5) | 0.51% | — | Wpbookingcalendar Secure Downloads | 15/5/2025 | 17/6/2026 | The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php. | |
| Analizada | Media (5.4) | 0.31% | — | Freebiesdownload PVN Auth Popup | 15/5/2025 | 17/6/2026 | The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Analizada | Media (4.8) | 0.32% | — | Freebiesdownload PVN Auth Popup | 15/5/2025 | 17/6/2026 | The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (5.4) | 0.18% | — | Westerndeal Easy Digital Downloads Google Sheet ConnectorEDD Gsheetconnector | 15/5/2025 | 17/6/2026 | The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Aplazada | Alta (7.5) | 0.80% | — | Wpchill Download MonitorAI | 7/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects Download Monitor: from n/a through <= 5.0.22. | |
| Aplazada | Media (4.3) | 0.26% | — | M.code Media Library DownloaderAI | 24/4/2025 | 17/6/2026 | Missing Authorization vulnerability in M.Code Media Library Downloader media-library-downloader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media Library Downloader: from n/a through <= 1.3.1. | |
| Modificada | Media (5.4) | 0.22% | — | Plugin-planet Simple Download Counter | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter simple-download-counter allows Stored XSS.This issue affects Simple Download Counter: from n/a through <= 2.2. | |
| Aplazada | Alta (8.8) | 1.1% | — | Download ManagerAI | 19/4/2025 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the… | |
| Aplazada | Media (5.4) | 0.37% | — | Download ManagerAI | 18/4/2025 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.36% | — | Maennchen1 M1 DownloadlistAI | 8/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadList m1downloadlist allows Retrieve Embedded Sensitive Data.This issue affects m1.DownloadList: from n/a through <= 0.24. | |
| Aplazada | Alta (7.1) | 0.14% | — | Infoway Ebook DownloaderAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Infoway LLC Ebook Downloader ebook-downloader allows Cross Site Request Forgery.This issue affects Ebook Downloader: from n/a through <= 1.0. |