Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▼ 7 respecto a la semana anterior
Críticas / altas1273▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
2453 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | Churchadminplugin Church Admin | 16/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions. | |
| Modificada | Media (5.4) | 0.42% | — | Plugin-planet User Submitted Posts | 15/8/2023 | 17/6/2026 | El plugin User Submitted Posts para WordPress es vulnerable a Cross-Site Scripting (XSS) Almacenado a través del parámetro 'user-submitted-content' en versiones hasta, e incluyendo, 20230809 debido a insuficiente sanitización de entrada y escape de salida. Esto hace posible que atacantes no autenticados inyecten… | |
| Modificada | Media (4.8) | 2.2% | — | Brutalplugins WP Brutal AI | 14/8/2023 | 17/6/2026 | The WP Brutal AI WordPress plugin before 2.06 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.37% | — | Smartypantsplugins SP Project & Document Manager | 10/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Paymentsplugin WP Full Stripe Free | 8/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) almacenado autenticado con permisos de administrador o superior en el plugin Mammothology WP Full Stripe Free en versiones anteriores, e incluyendo la 1.6.1. | |
| Modificada | Media (4.8) | 0.37% | — | Anadnet Quick Page/post Redirect Plugin | 8/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anadnet Quick Page/Post Redirect Plugin plugin <= 5.2.3 versions. | |
| Modificada | Media (6.1) | 2.2% | — | Apache Felix Health Check Webconsole Plugin | 25/7/2023 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin… | |
| Modificada | Media (6.1) | 0.41% | — | Fivestarplugins Five Star Restaurant Menu | 25/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Pluginforage Woocommerce Product Categories Selection Widget | 25/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PluginForage WooCommerce Product Categories Selection Widget plugin <= 2.0 versions. | |
| Modificada | Media (6.1) | 0.57% | — | Ckeditor-wordcount-plugin Project Ckeditor-wordcount-plugin | 21/7/2023 | 17/6/2026 | ckeditor-wordcount-plugin es un complemento WordCount de código abierto para CKEditor. Se ha descubierto que el complemento `ckeditor-wordcount-plugin` para CKEditor4 es susceptible a Cross-Site Scripting al cambiar al modo de código fuente. Este problema se solucionó en la versión 1.17.12 del complemento… | |
| Modificada | Alta (7.5) | 0.67% | — | Advancedplugins Ultimateimagetool | 20/7/2023 | 17/6/2026 | In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop, a guest can download personal informations without restriction by performing a path traversal attack. | |
| Modificada | Crítica (9.8) | 1.0% | — | Prestashop Payplug | 18/7/2023 | 17/6/2026 | An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller. | |
| Modificada | Media (4.8) | 0.39% | — | Armemberplugin Armember | 18/7/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARMember (free), Repute InfoSystems ARMember (premium) plugins. | |
| Modificada | Alta (8.8) | 0.26% | — | Pluginpress Shortcode Imdb | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kemal YAZICI - PluginPress Shortcode IMDB plugin <= 6.0.8 versions. | |
| Modificada | Media (5.4) | 0.51% | — | Yarpp YET Another Related Posts Plugin | 18/7/2023 | 17/6/2026 | The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Alta (8.8) | 0.26% | — | Fivestarplugins Five Star Restaurant Menu | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions. | |
| Modificada | Media (6.5) | 1.1% | 💥 PoC | Belkin Wemo Smart Plug Wsp080 Firmware | 13/7/2023 | 17/6/2026 | Incorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP080 v1.2 allows attackers to cause a Denial of Service (DoS) via a crafted firmware file. | |
| Modificada | Media (4.3) | 0.39% | — | Inoplugs Wp-backgrounds-lite | 12/7/2023 | 17/6/2026 | The WP-Backgrounds Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the ino_save_data() function. This makes it possible for unauthenticated attackers to save meta data via a forged request granted they… | |
| Modificada | Alta (8.8) | 0.32% | — | Armemberplugin Armember | 12/7/2023 | 17/6/2026 | The ARMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.5. This is due to missing or incorrect nonce validation on the arm_check_user_cap function. This makes it possible for unauthenticated attackers to perform multiple unauthorized actions via a forged… | |
| Modificada | Media (4.3) | 0.38% | — | Coolplugins Process Steps Template Designer | 12/7/2023 | 17/6/2026 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request… | |
| Modificada | Media (4.3) | 0.38% | — | Goldplugins Custom Banners | 12/7/2023 | 17/6/2026 | The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted… | |
| Modificada | Alta (8.8) | 0.31% | — | Wpplugin Paypal & Stripe Add-on | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9.3 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Wpplugin Contact Form 7 Redirect & Thank YOU Page | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 Redirect & Thank You Page plugin <= 1.0.3 versions. | |
| Modificada | Media (4.3) | 0.39% | — | Goldplugins Staff Directory Plugin | 1/7/2023 | 17/6/2026 | The Staff Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request… |