Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 87 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
2459 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.38% | — | Weplugins WP Maps | 4/4/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Essentialplugin Popup Anything | 29/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Fullworksplugins Quick Event Manager | 28/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions. | |
| Modificada | Media (4.3) | 0.25% | — | Hasthemes WP Plugin Manager | 27/3/2023 | 17/6/2026 | The WP Plugin Manager WordPress plugin before 1.1.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Media (5.4) | 0.56% | — | Really-simple-plugins Complianz | 27/3/2023 | 17/6/2026 | The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site… | |
| Modificada | Alta (8.8) | 0.91% | — | E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+7 | 27/3/2023 | 17/6/2026 | The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before… | |
| Modificada | Media (5.4) | 0.44% | — | Pluginus Inpost Gallery | 22/3/2023 | 17/6/2026 | The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which can only be triggered by an authenticated user. | |
| Modificada | Media (5.4) | 0.44% | — | Pluginus Wordpress Meta Data AND Taxonomies Filter | 22/3/2023 | 17/6/2026 | The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'tax_name' parameter of the mdf_get_tax_options_in_widget action, which can only be triggered by an authenticated user. | |
| Modificada | Alta (8.8) | 0.87% | — | Plugin Waiting | 22/3/2023 | 17/6/2026 | The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action. | |
| Modificada | Alta (8.8) | 0.26% | — | Obox Launchpad - Coming Soon & Maintenance Mode Plugin | 17/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Obox Themes Launchpad – Coming Soon & Maintenance Mode plugin <= 1.0.13 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Booking-wp-plugin Bookly | 17/3/2023 | 17/6/2026 | The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Alta (8.8) | 1.2% | — | Tenable NessusTenable Plugin Feed | 15/3/2023 | 17/6/2026 | A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets. | |
| Modificada | Alta (8.8) | 0.63% | — | Richplugins Plugin FOR Google Reviews | 15/3/2023 | 17/6/2026 | SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Hmplugin Accept Stripe Donation - Aidwp | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin Accept Stripe Donation – AidWP plugin <= 3.1.5 versions. | |
| Modificada | Media (5.4) | 0.23% | — | Fullworksplugins Quick Event Manager | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registration actions (delete, delete all, edit, update). | |
| Modificada | Media (4.3) | 0.23% | — | Checkoutplugins Stripe Payments FOR Woocommerce | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce plugin <= 1.4.10 leads to settings change. | |
| Modificada | Media (5.4) | 0.53% | — | Gsplugins GS Insever Portfolio | 27/2/2023 | 17/6/2026 | The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.1) | 0.55% | — | Esdoc-publish-html-plugin | 21/2/2023 | 17/6/2026 | esdoc-publish-html-plugin is a plugin for the document maintenance software ESDoc. TheHTML sanitizer in esdoc-publish-html-plugin 1.1.2 and prior can be bypassed which may lead to cross-site scripting (XSS) issues. There are no known patches for this issue. | |
| Modificada | Media (5.4) | 0.46% | — | Gsplugins GS Portfolio FOR Envato | 21/2/2023 | 17/6/2026 | The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.61% | — | Gsplugins GS Books Showcase | 21/2/2023 | 17/6/2026 | The GS Books Showcase WordPress plugin before 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.46% | — | Gsplugins GS Filterable Portfolio | 21/2/2023 | 17/6/2026 | The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.46% | — | Gsplugins GS Products Slider | 21/2/2023 | 17/6/2026 | The GS Products Slider for WooCommerce WordPress plugin before 1.5.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.53% | — | Quick-plugins Loan Comparison | 21/2/2023 | 17/6/2026 | The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.47% | — | Essentialplugin Product Slider AND Carousel With Category With Woocommerce | 21/2/2023 | 17/6/2026 | The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Alta (8.8) | 0.36% | — | Submitbymailplugin Project Submitbymailplugin | 20/2/2023 | 17/6/2026 | A vulnerability was found in arnoldle submitByMailPlugin 1.0b2.9 and classified as problematic. This issue affects some unknown processing of the file edit_list.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. Upgrading to version 1.0b2.9a is able to address this issue.… |