Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

228 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.62%—Onyaktech Comments PRO Project Onyaktech Comments PRO7/9/202117/6/2026
An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment.
ModificadaAlta (7.2)1.5%—Comment Highlighter Project Comment Highlighter6/9/202117/6/2026
A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
ModificadaCrítica (9.8)1.9%—Edit Comments Project Edit Comments23/8/202117/6/2026
The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue
ModificadaMedia (5.3)0.98%—Wphappycoders Comments Like Dislike21/6/202117/6/2026
The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin appears to have some Restriction modes,…
ModificadaMedia (5.3)2.1%💥 ExploitThrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+1612/4/202117/6/2026
The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive…
ModificadaAlta (7.5)21%💥 ExploitAdvanced Comment System Project Advanced Comment System23/12/202017/6/2026
ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI. NOTE: this might be the same as CVE-2009-4623
ModificadaAlta (8.2)12%💥 ExploitPrestashop Productcomments3/12/202017/6/2026
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
ModificadaMedia (6.1)0.89%—Prestashop Product Comments16/11/202017/6/2026
In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0
ModificadaCrítica (9.8)2.4%—Atlassian Jira Comment9/11/202017/6/2026
The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue comment.
ModificadaAlta (8.1)0.61%—Nodebb Blog Comments26/8/202017/6/2026
In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.
ModificadaMedia (5.4)0.94%—Munkireport Project Comment23/7/202017/6/2026
A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment.
ModificadaMedia (5.4)0.54%—Verbb Comments5/6/202017/6/2026
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.
ModificadaMedia (5.4)0.54%—Verbb Comments5/6/202017/6/2026
An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name.
ModificadaMedia (6.5)0.43%—Verbb Comments5/6/202017/6/2026
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
ModificadaMedia (6.1)1.8%💥 ExploitLivefyre Livecomments27/12/201917/6/2026
Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded picture.
ModificadaMedia (6.1)1.2%—Videowhisper Video Comments Webcam Recorder27/12/201917/6/2026
Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.
ModificadaMedia (6.5)1.1%—Jenkins Violation Comments TO Gitlab25/9/201917/6/2026
Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
ModificadaMedia (6.5)1.1%—Jenkins Violation Comments TO Gitlab25/9/201917/6/2026
Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
ModificadaMedia (6.1)0.98%—Spot.im Comments10/9/201917/6/2026
The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)0.91%—Bologer Anycomment27/8/201917/6/2026
The anycomment plugin before 0.0.33 for WordPress has XSS.
ModificadaMedia (4.3)0.50%—Pippinsplugins Featured Comments22/8/201917/6/2026
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
ModificadaMedia (6.1)0.91%—Embed Images IN Comments Project Embed Images IN Comments21/8/201917/6/2026
The embed-comment-images plugin before 0.6 for WordPress has XSS.
ModificadaMedia (6.1)1.4%—Advanced Comment System Project Advanced Comment System21/3/201917/6/2026
internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain a reflected cross-site scripting vulnerability via ACS_path. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript…
ModificadaCrítica (9.8)4.2%💥 ExploitAdvanced Comment System Project Advanced Comment System29/11/201817/6/2026
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in the "page" parameter. NOTE: The product is…
ModificadaAlta (7.8)5.1%💥 ExploitWebtoffee Wordpress Comments Import AND Export19/6/201817/6/2026
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.