Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.22% | — | Mesa Mesa Reservation WidgetAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gslauraspeck Mesa Mesa Reservation Widget mesa-mesa-reservation-widget allows Stored XSS.This issue affects Mesa Mesa Reservation Widget: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.12% | — | Nonletter Newsletter Subscription Widget FOR SendblasterAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nonletter Newsletter subscription optin module newsletter-subscription-widget-for-sendblaster allows Stored XSS.This issue affects Newsletter subscription optin module: from n/a through <= 1.2.9. | |
| Aplazada | Alta (7.1) | 0.23% | — | Themeblvd Widget AreasAI | 28/8/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason Theme Blvd Widget Areas theme-blvd-widget-areas allows Reflected XSS.This issue affects Theme Blvd Widget Areas: from n/a through <= 1.3.0. | |
| Aplazada | Crítica (9.3) | 1.5% | 💥 Exploit | Miguel Useche JS Archive ListAIJquery Archive List WidgetAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows SQL Injection.This issue affects JS Archive List: from n/a through < 6.1.6. | |
| Aplazada | Alta (8.1) | 0.56% | — | Radiustheme Widget FOR Google ReviewsAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Widget for Google Reviews business-reviews-wp allows PHP Local File Inclusion.This issue affects Widget for Google Reviews: from n/a through <= 1.0.15. | |
| Aplazada | Media (6.4) | 0.24% | — | Stratum Elementor WidgetsAI | 1/8/2025 | 17/6/2026 | The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Google Maps and Image Hotspot widgets in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Modificada | Crítica (9.8) | 1.4% | — | Hasthemes Download Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks | 15/7/2025 | 17/6/2026 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation in the handle_files_upload() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated… | |
| Modificada | Crítica (9.8) | 1.1% | — | Hasthemes Download Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks | 15/7/2025 | 17/6/2026 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated… | |
| Modificada | Crítica (9.8) | 1.7% | 💥 PoC | Hasthemes Download Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks | 15/7/2025 | 17/6/2026 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the temp_file_upload() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers… | |
| Analizada | Alta (8.8) | 0.81% | — | Radiustheme Widget FOR Google Reviews | 8/7/2025 | 17/6/2026 | The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing the… | |
| Aplazada | Alta (8.5) | 0.29% | — | Cybio Gallery-widgetAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cybio Gallery Widget gallery-widget allows SQL Injection.This issue affects Gallery Widget: from n/a through <= 1.2.1. | |
| Aplazada | Crítica (9.1) | 2.4% | 💥 Exploit | Bitto.kazi Custom Login AND Signup WidgetAI | 1/7/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget allows Code Injection.This issue affects Custom Login And Signup Widget: from n/a through <= 1.0. | |
| Analizada | Media (5.4) | 0.24% | — | Ieonly EZ SQL Reports Shortcode Widget AND DB Backup | 29/6/2025 | 17/6/2026 | The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SQLREPORT shortcode in all versions up to, and including, 5.25.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.23% | — | Douglaskarr Podcast Feed Player WidgetAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in douglaskarr Podcast Feed Player Widget and Shortcode podcast-feed-player-widget allows Stored XSS.This issue affects Podcast Feed Player Widget and Shortcode: from n/a through <= 2.2.0. | |
| Aplazada | Media (4.3) | 0.27% | — | Morten Dalgaard Johansen Dashboard Widget SidebarAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Morten Dalgaard Johansen Dashboard Widget Sidebar dashboard-widget-sidebar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dashboard Widget Sidebar: from n/a through <= 1.2.3. | |
| Aplazada | Alta (8.8) | 0.42% | — | Accuweather AND Custom RSS WidgetAI | 25/6/2025 | 17/6/2026 | A cross-site scripting vulnerability exists in the AccuWeather and Custom RSS widget that allows an unauthenticated user to replace the RSS feed URL with a malicious one. | |
| Analizada | Media (5.4) | 0.19% | — | Siteorigin Widgets Bundle | 25/6/2025 | 17/6/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM Element Attribute in all versions up to, and including, 1.68.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (4.3) | 0.15% | — | Oganro XML Travel Portal WidgetAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Oganro XML Travel Portal Widget oganro-reservation-widget allows Cross Site Request Forgery.This issue affects XML Travel Portal Widget: from n/a through <= 2.0. | |
| Aplazada | Media (4.3) | 0.15% | — | Oganro Travel Portal Search Widget FOR Hotelbeds Apitude APIAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Oganro Oganro Travel Portal Search Widget for HotelBeds APITUDE API oganro-travel-portal-search-widget-for-hotelbeds-apitude-api allows Cross Site Request Forgery.This issue affects Oganro Travel Portal Search Widget for HotelBeds APITUDE API: from n/a through <= 1.0. | |
| Modificada | Media (5.4) | 0.25% | — | Catchsquare WP Social Widget | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget wp-social-widget allows Stored XSS.This issue affects WP Social Widget: from n/a through <= 2.3. | |
| Aplazada | Alta (7.1) | 0.14% | — | Otwthemes Widgetize Pages LightAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Stored XSS.This issue affects Widgetize Pages Light: from n/a through <= 3.0. | |
| Aplazada | Media (5.9) | 0.25% | — | Debashish Iframe WidgetAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debashish IFrame Widget iframe-widget allows Stored XSS.This issue affects IFrame Widget: from n/a through <= 4.1. | |
| Aplazada | Media (6.5) | 0.20% | — | ABU Huraira BIN Aman Widgetkit FOR ElementorAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abu Huraira Bin Aman WidgetKit widgetkit-for-elementor allows Stored XSS.This issue affects WidgetKit: from n/a through <= 2.5.4. | |
| Aplazada | Media (6.5) | 0.35% | — | Experto CTA WidgetAI | 23/5/2025 | 17/6/2026 | Missing Authorization vulnerability in UX Design Experts Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin experto-cta-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin: from… | |
| Aplazada | Alta (7.1) | 0.27% | — | Ctltwp Section WidgetAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ctltwp Section Widget section-widget allows Reflected XSS.This issue affects Section Widget: from n/a through <= 3.3.1. |