Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.27% | — | Toolbar ExtrasAI | 22/5/2024 | 17/6/2026 | The Toolbar Extras for Elementor & More – WordPress Admin Bar Enhanced plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tbex-version' shortcode in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Analizada | Crítica (9.8) | 0.68% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in By Averta Shortcodes and extra features for Phlox theme allows PHP Local File Inclusion.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.14.0. | |
| Modificada | Media (5.4) | 0.34% | — | Envothemes Envo Extra | 16/5/2024 | 17/6/2026 | The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 1.8.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject… | |
| Modificada | Media (5.4) | 0.35% | — | Sinaextra Sina Extension FOR Elementor | 15/5/2024 | 17/6/2026 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina Particle Layer widget in all versions up to, and including, 3.5.3 due to insufficient input… | |
| Modificada | Media (5.4) | 0.39% | — | Sinaextra Sina Extension FOR Elementor | 14/5/2024 | 17/6/2026 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via several parameters in versions up to, and including, 3.5.3 due to insufficient input sanitization and output… | |
| Aplazada | Media (6.4) | 0.51% | — | Elegantthemes DiviAIElegantthemes ExtraAIElegantthemes Divi Page BuilderAI | 14/5/2024 | 17/6/2026 | The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.53% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 2/5/2024 | 17/6/2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion Widget in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor… | |
| Modificada | Media (5.4) | 0.54% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 2/5/2024 | 17/6/2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_gmaps' shortcode in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.4) | 0.40% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 2/5/2024 | 17/6/2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML Element in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access… | |
| Modificada | Media (5.4) | 0.41% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 2/5/2024 | 17/6/2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.40% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 2/5/2024 | 17/6/2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor… | |
| Modificada | Alta (7.5) | 0.87% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 2/5/2024 | 17/6/2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.17.5 via deserialization of untrusted input from the vulnerable 'id' parameter in the 'auxin_template_control_importer' function. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.43% | — | Sinaextra Sina Extension FOR Elementor | 25/4/2024 | 17/6/2026 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina Fancy Text Widget in all versions up to, and including, 3.5.2 due to insufficient input… | |
| Aplazada | Media (6.5) | 0.32% | — | Attestawp Attesa ExtraAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AttesaWP Attesa Extra allows Stored XSS.This issue affects Attesa Extra: from n/a through 1.3.9. | |
| Modificada | Media (5.4) | 0.32% | — | Envothemes Envo Extra | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra allows Stored XSS.This issue affects Envo Extra: from n/a through 1.8.11. | |
| Modificada | Media (5.4) | 0.40% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 16/4/2024 | 17/6/2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_timeline shortcode in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping on user supplied attributes such as thumb_mode and… | |
| Aplazada | Media (4.3) | 0.20% | — | Rednao Extra Product Options Builder FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RedNao Extra Product Options Builder for WooCommerce.This issue affects Extra Product Options Builder for WooCommerce: from n/a through 1.2.104. | |
| Modificada | Media (6.4) | 0.51% | — | Oceanwp Ocean Extra | 9/4/2024 | 17/6/2026 | The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘twitter_username’ parameter in versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to… | |
| Analizada | Alta (8.8) | 0.36% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 1/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Averta Shortcodes and extra features for Phlox theme auxin-elements.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.7. | |
| Modificada | Media (5.4) | 0.34% | — | Sinaextra Sina Extension FOR Elementor | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SinaExtra Sina Extension for Elementor allows Stored XSS.This issue affects Sina Extension for Elementor: from n/a through 3.5.0. | |
| Modificada | Media (6.1) | 0.37% | — | Oxyextras | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPLIT Pty Ltd OxyExtras allows Reflected XSS.This issue affects OxyExtras: from n/a through 1.4.4. | |
| Analizada | Media (4.3) | 0.30% | — | Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT | 13/3/2024 | 11/8/2026 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on several ajax actions. This makes it possible for unauthenticated attackers to invoke those actions via a… | |
| Analizada | Media (4.3) | 0.53% | — | Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT | 13/3/2024 | 11/8/2026 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0. This is due to missing or incorrect capability checks on several ajax actions. This makes it possible for authenticated attackers, with subscriber access or higher, to… | |
| Modificada | Media (5.4) | 0.46% | — | Oceanwp Ocean Extra | 29/2/2024 | 17/6/2026 | The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom fields in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web… | |
| Modificada | Crítica (9.8) | 1.6% | — | Rpm-software-management MockFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/1/2024 | 17/6/2026 | The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the expansion and execution of Jinja2 templates, which may be included in… |