Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

250 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.27%—Nxsn WP Hide Pages9/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Huseyin Berberoglu WP Hide Pages plugin <= 1.0 versions.
ModificadaAlta (8.8)0.44%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV5/10/202317/6/2026
A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.7.3 is able to address this issue. The identifier of…
ModificadaMedia (6.4)0.89%—Hitreach Allow PHP IN Posts AND Pages16/9/202317/6/2026
The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.
ModificadaMedia (5.4)0.36%—Webmechanix ADD Posts TO Pages10/8/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Arsham Mirshah Add Posts to Pages plugin <= 1.4.1 versions.
ModificadaMedia (6.8)0.40%—Cmscommander WP Shopping Pages7/8/202317/6/2026
The WP Shopping Pages WordPress plugin through 1.14 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
ModificadaMedia (6.1)0.59%—Oomphinc View ALL Post's Pages10/7/202317/6/2026
A vulnerability, which was classified as problematic, has been found in View All Posts Page Plugin up to 0.9.0 on WordPress. This issue affects the function action_admin_notices_activation of the file view-all-posts-pages.php. The manipulation leads to cross site scripting. The attack may be initiated remotely.…
ModificadaMedia (6.1)0.46%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages5/6/202317/6/2026
The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaBaja (3.8)0.66%—Kylephillips Nested Pages31/5/202317/6/2026
The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings.
ModificadaMedia (6.5)0.57%—SAP Netweaver AS Abap Business Server Pages11/4/202317/6/2026
SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters in certain circumstances which can consume the server's resources sufficiently to make…
ModificadaMedia (6.1)0.67%—Inboundnow Landing-pages6/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in Landing Pages Plugin up to 1.8.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.8.8 is able to address this issue. The…
ModificadaMedia (5.4)0.49%—List Pages Shortcode Project List Pages Shortcode27/2/202317/6/2026
The List Pages Shortcode WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as…
ModificadaMedia (6.1)0.36%—SAP Netweaver AS Abap Business Server Pages14/2/202317/6/2026
Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack. As a result, an…
ModificadaMedia (6.1)0.39%—SAP Netweaver AS Abap Business Server Pages14/2/202317/6/2026
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This…
ModificadaMedia (5.4)0.71%—Widgets ON Pages Project Widgets ON Pages13/2/202317/6/2026
The Widgets on Pages WordPress plugin before 1.8.0 does not validate and escape its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaMedia (5.4)0.53%—Caterhamcomputing CC Child Pages30/1/202317/6/2026
The CC Child Pages WordPress plugin before 1.43 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaMedia (5.4)0.53%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages16/1/202317/6/2026
The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as…
ModificadaMedia (5.4)0.53%—Insert Pages Project Insert Pages16/1/202317/6/2026
The Insert Pages WordPress plugin before 3.7.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaMedia (5.4)0.47%—Ipages Flipbook Project Ipages Flipbook9/1/202317/6/2026
The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (4.2)0.42%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV17/10/202217/6/2026
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce
ModificadaAlta (7.2)1.1%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV17/10/202217/6/2026
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
ModificadaCrítica (9.8)1.1%—Gh-pages Project Gh-pages12/10/202217/6/2026
Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js.
ModificadaMedia (5.4)0.51%—AS - Create Pinterest Pinboard Pages Project AS - Create Pinterest Pinboard Pages23/8/202217/6/2026
Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash soni's AS – Create Pinterest Pinboard Pages plugin <= 1.0 at WordPress.
ModificadaAlta (8.8)0.60%—Insights From Google Pagespeed Project Insights From Google Pagespeed17/7/202217/6/2026
The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
ModificadaMedia (4.8)0.67%—Kylephillips Nested Pages27/6/202217/6/2026
The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed
ModificadaAlta (7.2)1.3%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV27/6/202217/6/2026
The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks
Orbitaley — Vulnerabilidades