Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.62% | — | Onyaktech Comments PRO Project Onyaktech Comments PRO | 7/9/2021 | 17/6/2026 | An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment. | |
| Modificada | Alta (7.2) | 1.5% | — | Comment Highlighter Project Comment Highlighter | 6/9/2021 | 17/6/2026 | A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. | |
| Modificada | Crítica (9.8) | 1.9% | — | Edit Comments Project Edit Comments | 23/8/2021 | 17/6/2026 | The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue | |
| Modificada | Media (5.3) | 0.98% | — | Wphappycoders Comments Like Dislike | 21/6/2021 | 17/6/2026 | The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin appears to have some Restriction modes,… | |
| Modificada | Media (5.3) | 2.1% | 💥 Exploit | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+16 | 12/4/2021 | 17/6/2026 | The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive… | |
| Modificada | Alta (7.5) | 21% | 💥 Exploit | Advanced Comment System Project Advanced Comment System | 23/12/2020 | 17/6/2026 | ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI. NOTE: this might be the same as CVE-2009-4623 | |
| Modificada | Alta (8.2) | 12% | 💥 Exploit | Prestashop Productcomments | 3/12/2020 | 17/6/2026 | In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module. | |
| Modificada | Media (6.1) | 0.89% | — | Prestashop Product Comments | 16/11/2020 | 17/6/2026 | In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0 | |
| Modificada | Crítica (9.8) | 2.4% | — | Atlassian Jira Comment | 9/11/2020 | 17/6/2026 | The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue comment. | |
| Modificada | Alta (8.1) | 0.61% | — | Nodebb Blog Comments | 26/8/2020 | 17/6/2026 | In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation. | |
| Modificada | Media (5.4) | 0.94% | — | Munkireport Project Comment | 23/7/2020 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment. | |
| Modificada | Media (5.4) | 0.54% | — | Verbb Comments | 5/6/2020 | 17/6/2026 | An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name. | |
| Modificada | Media (5.4) | 0.54% | — | Verbb Comments | 5/6/2020 | 17/6/2026 | An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name. | |
| Modificada | Media (6.5) | 0.43% | — | Verbb Comments | 5/6/2020 | 17/6/2026 | An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity. | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Livefyre Livecomments | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded picture. | |
| Modificada | Media (6.1) | 1.2% | — | Videowhisper Video Comments Webcam Recorder | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Media (6.5) | 1.1% | — | Jenkins Violation Comments TO Gitlab | 25/9/2019 | 17/6/2026 | Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (6.5) | 1.1% | — | Jenkins Violation Comments TO Gitlab | 25/9/2019 | 17/6/2026 | Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system. | |
| Modificada | Media (6.1) | 0.98% | — | Spot.im Comments | 10/9/2019 | 17/6/2026 | The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.91% | — | Bologer Anycomment | 27/8/2019 | 17/6/2026 | The anycomment plugin before 0.0.33 for WordPress has XSS. | |
| Modificada | Media (4.3) | 0.50% | — | Pippinsplugins Featured Comments | 22/8/2019 | 17/6/2026 | The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment. | |
| Modificada | Media (6.1) | 0.91% | — | Embed Images IN Comments Project Embed Images IN Comments | 21/8/2019 | 17/6/2026 | The embed-comment-images plugin before 0.6 for WordPress has XSS. | |
| Modificada | Media (6.1) | 1.4% | — | Advanced Comment System Project Advanced Comment System | 21/3/2019 | 17/6/2026 | internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain a reflected cross-site scripting vulnerability via ACS_path. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript… | |
| Modificada | Crítica (9.8) | 4.2% | 💥 Exploit | Advanced Comment System Project Advanced Comment System | 29/11/2018 | 17/6/2026 | internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in the "page" parameter. NOTE: The product is… | |
| Modificada | Alta (7.8) | 5.1% | 💥 Exploit | Webtoffee Wordpress Comments Import AND Export | 19/6/2018 | 17/6/2026 | The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. |