Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

644 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.9)0.28%—Wpindeed Ultimate Learning PROAI16/12/202517/6/2026
Missing Authorization vulnerability in azzaroco Ultimate Learning Pro indeed-learning-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Learning Pro: from n/a through <= 3.9.3.
AplazadaMedia (4.3)0.12%—Rustaurius Ultimate FAQAI9/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate FAQ ultimate-faqs allows Cross Site Request Forgery.This issue affects Ultimate FAQ: from n/a through <= 2.4.3.
AplazadaMedia (4.3)0.23%—Ultimatemember ForumwpAI9/12/20257/10/2026
Missing Authorization vulnerability in Ultimate Member ForumWP forumwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ForumWP: from n/a through <= 2.1.4.
AplazadaMedia (6.5)0.24%—Wpmet WP Ultimate ReviewAI9/12/20257/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows DOM-Based XSS.This issue affects Wp Ultimate Review: from n/a through <= 2.3.7.
AplazadaMedia (6.4)0.18%—Shortcodes UltimateAI23/11/202517/6/2026
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.4.5 via the su_shortcode_csv_table function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to…
AplazadaMedia (5.3)0.24%—Ultimate Member Widgets FOR ElementorAI20/11/202517/6/2026
The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handle_filter_users function in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to extract partial…
AplazadaMedia (4.3)0.21%—Wpswings Woocommerce Ultimate Points AND RewardsAI13/11/20257/10/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPSwings WooCommerce Ultimate Points And Rewards woocommerce-ultimate-points-and-rewards allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce Ultimate Points And Rewards: from n/a through <= 2.10.2.
AplazadaMedia (4.3)0.26%—WP Import Ultimate CSV XML ImporterAI12/11/202517/6/2026
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attackers, with Author-level…
AnalizadaMedia (5.1)0.17%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in '/clients/save_contact/'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/tickets/save'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1' in '/estimate_requests/save_estimate_request'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'reply_message' in '/messages/reply'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in'/projects/save'.
ModificadaMedia (6.5)0.38%—Fairsketch Rise Ultimate Project Manager3/11/20255/7/2026
FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization checks in the ticketing/commenting API.
AnalizadaAlta (8.7)0.41%💥 PoCUltimatefosters Ultimatepos3/11/202517/6/2026
A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper escaping in the admin log panel page in the 'reference No.' field. This flaw allows an authenticated attacker to execute…
AplazadaMedia (6.5)0.17%—Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI27/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Stored XSS.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through < 3.21.1.
AplazadaMedia (6.5)0.18%—Themepoints TAB UltimateAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Tab Ultimate tabs-pro.This issue affects Tab Ultimate: from n/a through <= 1.8.
AplazadaCrítica (9.8)0.58%—Quantumcloud KBX PRO UltimateAI22/10/202517/6/2026
Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Object Injection.This issue affects KBx Pro Ultimate: from n/a through <= 8.0.5.
AplazadaMedia (6.5)0.22%—Dotcamp Ultimate BlocksAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks ultimate-blocks allows Stored XSS.This issue affects Ultimate Blocks: from n/a through <= 3.3.6.
AnalizadaMedia (6.5)0.29%—Myupb Ultimate PHP Board16/10/202517/6/2026
SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.
AnalizadaMedia (6.1)0.27%—Myupb Ultimate PHP Board16/10/202517/6/2026
Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.
AplazadaMedia (6.4)0.29%—Ultimate Addons FOR WpbakeryAI16/10/202517/6/2026
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 3.21.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaAlta (8.1)1.1%💥 PoCFairsketch Rise Ultimate Project Manager10/10/20255/7/2026
Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise.…
AplazadaMedia (4.3)0.18%—Brainstormforce Ultimate Addons FOR ElementorAI6/10/202517/6/2026
The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability.
Orbitaley — Vulnerabilidades