Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
378 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.31% | — | Idiom Easy Social Share Buttons | 10/10/2024 | 17/6/2026 | The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Alta (7.5) | 0.56% | — | Istmoplugins Instant-chat-floating-button-for-wordpress-websitesAI | 5/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Instant Chat Floating Button for WordPress Websites instant-chat-wp allows PHP Local File Inclusion.This issue affects Instant Chat Floating Button for WordPress Websites: from n/a through <= 1.0.5. | |
| Analizada | Alta (8.8) | 0.35% | — | Supsystic SliderSupsystic Social Share Buttons | 26/9/2024 | 17/6/2026 | Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons by Supsystic: from n/a through 2.2.9. | |
| Modificada | Media (6.1) | 0.18% | — | Likebtn Like Button Rating | 17/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LikeBtn Like Button Rating likebtn-like-button.This issue affects Like Button Rating: from n/a through <= 2.6.53. | |
| Analizada | Media (4.8) | 0.35% | — | Just-a-web-developer Floating Contact Button | 10/9/2024 | 17/6/2026 | The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Analizada | Media (5.3) | 0.44% | — | Maxfoundry Maxbuttons | 24/8/2024 | 17/6/2026 | The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to… | |
| Aplazada | Media (4.7) | 0.31% | — | Wpplugin Easy Paypal BUY NOW ButtonAI | 19/8/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Easy PayPal Buy Now Button.This issue affects Easy PayPal Buy Now Button: from n/a through 1.9. | |
| Aplazada | Media (5.9) | 0.27% | — | Virustran Button Contact VRAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VirusTran Button contact VR allows Stored XSS.This issue affects Button contact VR: from n/a through 4.7.3. | |
| Modificada | Media (5.4) | 0.26% | — | Prowcplugins Empty Cart Button FOR Woocommerce | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ProWCPlugins Empty Cart Button for WooCommerce allows Stored XSS.This issue affects Empty Cart Button for WooCommerce: from n/a through 1.3.8. | |
| Modificada | Media (5.4) | 0.31% | — | Inisev Social Media Share Buttons & Social Sharing Icons | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Inisev Social Media & Share Icons allows Stored XSS.This issue affects Social Media & Share Icons: from n/a through 2.9.1. | |
| Aplazada | Media (6.5) | 0.25% | — | Clicklabs Download Button FOR ElementorAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in clicklabs® Medienagentur Download Button for Elementor allows Stored XSS.This issue affects Download Button for Elementor: from n/a through 1.2.1. | |
| Analizada | Media (5.4) | 0.49% | — | Maxfoundry Maxbuttons | 13/7/2024 | 17/6/2026 | The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks | |
| Aplazada | Media (6.5) | 0.24% | — | Binarycarpenter Ultimate Custom ADD TO Cart Button Ajax FOR WoocommerceAI | 12/7/2024 | 17/6/2026 | Missing Authorization vulnerability in BinaryCarpenter Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter custom-add-to-cart-button-for-woocommerce.This issue affects Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter: from n/a through <= 1.222.17. | |
| Modificada | Media (5.4) | 0.17% | — | Varniinfotech Floating Social Buttons | 29/6/2024 | 17/6/2026 | The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the floating_social_buttons_option() function. This makes it possible for unauthenticated attackers to update the plugins… | |
| Aplazada | Baja (3.7) | 0.45% | — | BigbluebuttonAI | 28/6/2024 | 17/6/2026 | BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/bundle/ruby/2.7.0/gems/resque-2.6.0` directory with the goal of privilege escalation, potentially… | |
| Aplazada | Media (4.6) | 0.31% | — | BigbluebuttonAI | 28/6/2024 | 17/6/2026 | BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those parameters may be "role=moderator", allowing an attacker to join a… | |
| Modificada | Media (5.4) | 0.36% | — | Wolfiezero Spotify Play Button | 26/6/2024 | 17/6/2026 | The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.32% | — | Mohsinrasool Paypal PAY Now, BUY Now, Donation AND Cart Buttons Shortcode | 21/6/2024 | 17/6/2026 | The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site… | |
| Modificada | Media (4.8) | 0.32% | — | Mohsinrasool Paypal PAY Now, BUY Now, Donation AND Cart Buttons Shortcode | 21/6/2024 | 17/6/2026 | The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in… | |
| Modificada | Media (5.4) | 0.40% | — | Sharethis Simple Share Buttons Adder | 18/6/2024 | 17/6/2026 | The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Aplazada | Media (6.3) | 0.28% | — | Idiom Easy Social Share ButtonsAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in appscreo Easy Social Share Buttons.This issue affects Easy Social Share Buttons: from n/a through 9.4. | |
| Aplazada | Media (5.3) | 0.33% | — | Social Share PRO Social Share Icons AND Social Share ButtonsAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Social Share Pro Social Share Icons & Social Share Buttons.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.6.2. | |
| Aplazada | Media (5.3) | 0.42% | — | Artlosk Share ButtonsAI | 4/6/2024 | 17/6/2026 | The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links for posts and pages in all versions up to, and including, 3.43. This makes it possible for unauthenticated attackers to obtain the contents of password protected posts and pages. | |
| Aplazada | Media (5.9) | 0.26% | — | Xabier Miranda WP Back ButtonAI | 3/6/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Xabier Miranda WP Back Button allows Stored XSS.This issue affects WP Back Button: from n/a through 1.1.3. | |
| Modificada | Media (5.4) | 0.26% | — | Sharethis Share Buttons | 23/5/2024 | 17/6/2026 | The ShareThis Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sharethis-inline-button' shortcode in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… |