Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
196 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.1% | — | Auntvt Timo | 20/2/2024 | 17/6/2026 | An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component. | |
| Modificada | Crítica (9.8) | 0.59% | — | Remyandrade Testimonial Page Manager | 2/2/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This issue affects some unknown processing of the file delete-testimonial.php of the component HTTP GET Request Handler. The manipulation of the argument testimony leads to sql injection. The attack may be… | |
| Modificada | Media (6.1) | 0.48% | — | Remyandrade Testimonial Page Manager | 2/2/2024 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Testimonial Page Manager 1.0. This vulnerability affects unknown code of the file add-testimonial.php of the component HTTP POST Request Handler. The manipulation of the argument name/description/testimony leads to cross site scripting. The attack… | |
| Modificada | Alta (8.8) | 0.23% | — | Wpchill Strong Testimonials | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10. | |
| Modificada | Alta (8.8) | 0.25% | — | Presstigers Simple Testimonials Showcase | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Testimonials Showcase allows Cross Site Request Forgery.This issue affects Simple Testimonials Showcase: from n/a through 1.1.5. | |
| Modificada | Media (4.8) | 0.42% | — | I13websolution Easy Testimonial Slider AND Form | 25/10/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form allows Stored XSS.This issue affects Easy Testimonial Slider and Form: from n/a through 1.0.18. | |
| Modificada | Media (5.4) | 0.45% | — | Themepoints Super Testimonials | 20/10/2023 | 17/6/2026 | The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpsscode' shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5.4) | 0.47% | — | Sazzadh Testimonial Slider Shortcode | 16/10/2023 | 17/6/2026 | The Testimonial Slider Shortcode WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Modificada | Crítica (9.8) | 0.64% | — | Themevolty Theme Volty CMS Testimonial | 3/10/2023 | 17/6/2026 | Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Trustindex WP Testimonials | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Trustindex.Io WP Testimonials plugin <= 1.4.2 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Optimonk\ | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OptiMonk OptiMonk: Popups, Personalization & A/B Testing plugin <= 2.0.4 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Brandid Social Proof (testimonial) Slider | 10/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in brandiD Social Proof (Testimonial) Slider plugin <= 2.2.3 versions. | |
| Modificada | Media (4.3) | 0.46% | — | Goldplugins Easy Testimonials | 1/7/2023 | 17/6/2026 | The Easy Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request… | |
| Modificada | Media (4.8) | 0.77% | 💥 Exploit | Aajoda Testimonials | 27/6/2023 | 17/6/2026 | The Aajoda Testimonials WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.4) | 0.37% | — | Wpchill Strong Testimonials | 16/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 versions. | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Easy Testimonial Slider AND Form | 8/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form plugin <= 1.0.15 versions. | |
| Modificada | Media (5.4) | 0.43% | — | Bnecreative BNE Testimonials | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kerry Kline BNE Testimonials plugin <= 2.0.7 versions. | |
| Modificada | Media (6.1) | 0.38% | — | GC Testimonials Project GC Testimonials | 17/3/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Erin Garscadden GC Testimonials plugin <= 1.3.2 versions. | |
| Modificada | Media (6.1) | 0.74% | — | Webhostings WH Testimonials | 13/3/2023 | 17/6/2026 | The WH Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as wh_homepage, wh_text_short, wh_text_full and in versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.4) | 0.47% | — | WP Responsive Testimonials Slider AND Widget Project WP Responsive Testimonials Slider AND Widget | 21/2/2023 | 17/6/2026 | The WP Responsive Testimonials Slider And Widget WordPress plugin through 1.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.65% | — | Machothemes Strong Testimonials | 6/2/2023 | 17/6/2026 | The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.4) | 0.65% | — | Goldplugins Easy Testimonials | 6/2/2023 | 17/6/2026 | The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.4) | 0.47% | — | Shapedplugin Real Testimonials | 16/1/2023 | 17/6/2026 | The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Crítica (9.8) | 0.93% | — | Multimon-ng Project Multimon-ng | 19/12/2022 | 17/6/2026 | A vulnerability was found in multimon-ng. It has been rated as critical. This issue affects the function add_ch of the file demod_flex.c. The manipulation of the argument ch leads to format string. Upgrading to version 1.2.0 is able to address this issue. The name of the patch is… | |
| Analizada | Media (4.8) | 0.53% | — | Themepoints Super Testimonials | 14/11/2022 | 17/6/2026 | The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. |