Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
226 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.20% | — | Dfactory Post Views CounterAI | 12/4/2024 | 17/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Post Views Counter <= 1.4.4 versions. | |
| Aplazada | Alta (8) | 0.53% | — | Trustindex Widgets FOR Google ReviewsAI | 26/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2. | |
| Aplazada | Media (4.3) | 0.20% | — | Saleswonder Builder FOR Woocommerce Reviews Shortcodes ReviewshortAI | 19/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias Builder for WooCommerce reviews shortcodes – ReviewShort woo-product-reviews-shortcode.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through <= 1.01.3. | |
| Aplazada | Media (5.9) | 0.32% | — | Geminilabs Site ReviewsAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gemini Labs Site Reviews site-reviews.This issue affects Site Reviews: from n/a through <= 6.11.6. | |
| Modificada | Media (6.1) | 0.38% | — | Etoilewebdesign Ultimate Reviews | 15/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8. | |
| Aplazada | Media (6.4) | 0.55% | — | Geminilabs Site ReviewsAI | 13/3/2024 | 17/6/2026 | The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary… | |
| Modificada | Media (5.3) | 0.41% | — | Cusrev Customer Reviews FOR Woocommerce | 29/2/2024 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to submit reviews with arbitrary email… | |
| Modificada | Media (4.3) | 0.34% | — | Cusrev Customer Reviews FOR Woocommerce | 28/2/2024 | 17/6/2026 | Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1. | |
| Modificada | Media (4.8) | 0.50% | — | Contentviewspro Content Views | 5/2/2024 | 17/6/2026 | The Content Views – Post Grid, Slider, Accordion (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (4.3) | 0.23% | — | Formviewswp Views FOR Wpforms | 5/2/2024 | 17/6/2026 | The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.2. This is due to missing or incorrect nonce validation on the 'create_view' function. This makes it possible for unauthenticated… | |
| Modificada | Media (4.3) | 0.23% | — | Formviewswp Views FOR Wpforms | 5/2/2024 | 17/6/2026 | The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.2. This is due to missing or incorrect nonce validation on the 'save_view' function. This makes it possible for unauthenticated… | |
| Modificada | Media (4.3) | 0.36% | — | Formviewswp Views FOR Wpforms | 5/2/2024 | 17/6/2026 | The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_form_fields' function in all versions up to, and including, 3.2.2. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.42% | — | Formviewswp Views FOR Wpforms | 5/2/2024 | 17/6/2026 | The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'create_view' function in all versions up to, and including, 3.2.2. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.42% | — | Formviewswp Views FOR Wpforms | 5/2/2024 | 17/6/2026 | The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_view' function in all versions up to, and including, 3.2.2. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.61% | — | Richplugins Plugin FOR Google Reviews | 5/2/2024 | 17/6/2026 | This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'place_id' attribute. This makes it possible for authenticated attackers with contributor-level and above… | |
| Modificada | Media (6.1) | 0.33% | — | Cybernetikz Post Views Stats | 31/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberNetikz Post views Stats post-views-stats allows DOM-Based XSS.This issue affects Post views Stats: from n/a through <= 1.4.1. | |
| Modificada | Media (5.4) | 0.53% | — | Cusrev Customer Reviews FOR Woocommerce | 16/1/2024 | 17/6/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 1.1% | — | Cusrev Customer Reviews FOR Woocommerce | 11/1/2024 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to… | |
| Modificada | Alta (8.8) | 0.26% | — | Reviewsignal Wpperformancetester | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kevin Ohashi WPPerformanceTester.This issue affects WPPerformanceTester: from n/a through 2.0.0. | |
| Modificada | Media (4.3) | 0.52% | — | Gowebsolutions WP Customer Reviews | 22/11/2023 | 17/6/2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.6.6 via the ajax_enabled_posts function. This can allow authenticated attackers to extract sensitive data such as post titles and slugs, including those of protected and trashed posts and… | |
| Modificada | Crítica (9.8) | 0.70% | — | Geminilabs Site Reviews | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Paul Ryley Site Reviews.This issue affects Site Reviews: from n/a through 6.2.0. | |
| Modificada | Crítica (9.8) | 0.70% | — | Webtoffee Product Reviews Import Export FOR Woocommerce | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee Product Reviews Import Export for WooCommerce.This issue affects Product Reviews Import Export for WooCommerce: from n/a through 1.4.8. | |
| Modificada | Media (4.8) | 0.35% | — | Gowebsolutions WP Customer Reviews | 20/10/2023 | 17/6/2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (4.3) | 0.20% | — | Trustedindex Widgets FOR Google Reviews | 18/10/2023 | 17/6/2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.9. This is due to missing or incorrect nonce validation within setup_no_reg_header.php. This makes it possible for unauthenticated attackers to reset plugin settings and remove reviews… | |
| Modificada | Media (4.3) | 0.56% | — | Codesupply Absolute Reviews | 12/7/2023 | 17/6/2026 | The Absolute Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on the metabox_review_save() function. This makes it possible for unauthenticated attackers to save meta tags via a forged request granted… |