Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | Tychesoftwares Product Input Fields FOR Woocommerce | 8/3/2025 | 17/6/2026 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function in all versions up to, and including, 1.12.0. This may make it possible for unauthenticated attackers to upload… | |
| Analizada | Alta (7.1) | 0.38% | — | Sprintexperts WP Extra Fields | 26/2/2025 | 17/6/2026 | The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.1) | 0.15% | — | What3words Address FieldAI | 16/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in what3words what3words Address Field 3-word-address-validation-field allows Stored XSS.This issue affects what3words Address Field: from n/a through <= 4.0.15. | |
| Aplazada | Alta (7.1) | 0.39% | — | Faaiq Simple Custom Post Type Custom Field Simple Content Construction KITAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faaiq Simple Custom post type custom field simple-content-construction-kit allows Reflected XSS.This issue affects Simple Custom post type custom field: from n/a through <= 1.0.3. | |
| Aplazada | Alta (7.1) | 0.20% | — | Alicornea Category Custom FieldsAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in alicornea Category Custom Fields categorycustomfields allows Cross Site Request Forgery.This issue affects Category Custom Fields: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Oren Yomtov Mass Custom Fields ManagerAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Oren Yomtov Mass Custom Fields Manager mass-custom-fields-manager allows Reflected XSS.This issue affects Mass Custom Fields Manager: from n/a through <= 1.5. | |
| Analizada | Alta (7.3) | 0.35% | — | Allow ALL File Extensions FOR File Fields Project Allow ALL File Extensions FOR File Fields | 9/1/2025 | 17/6/2026 | Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*. | |
| Aplazada | Alta (7.1) | 0.43% | 💥 PoC | Custom Field FOR WP JOB ManagerAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in theme funda Custom Field For WP Job Manager custom-field-for-wp-job-manager allows Reflected XSS.This issue affects Custom Field For WP Job Manager: from n/a through <= 1.3. | |
| Aplazada | Alta (7.1) | 0.31% | — | Pjfc SyncfieldsAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pjfc SyncFields syncfields allows Reflected XSS.This issue affects SyncFields: from n/a through <= 2.1. | |
| Aplazada | Media (6.5) | 0.26% | — | Takashi Kitajima Smart Custom FieldsAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Kitajima Smart Custom Fields smart-custom-fields allows Stored XSS.This issue affects Smart Custom Fields: from n/a through <= 5.0.0. | |
| Aplazada | Media (4.3) | 0.30% | — | Justcoded Just Custom FieldsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in JustCoded / Alex Prokopenko Just Custom Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Just Custom Fields: from n/a through 3.3.2. | |
| Aplazada | Alta (7.7) | 0.49% | — | Teclib-edition FieldsAI | 26/12/2024 | 17/6/2026 | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13. | |
| Analizada | Media (5.3) | 0.58% | — | Codepeople Calculated Fields Form | 17/12/2024 | 17/6/2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width parameters for CAPTCHA images. This makes it possible for unauthenticated attackers to send multiple requests with large values, resulting in… | |
| Aplazada | Media (4.3) | 0.23% | — | Wpengine INC Advanced Custom Fields PROAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPENGINE, INC. Advanced Custom Fields PRO.This issue affects Advanced Custom Fields PRO: from n/a before 6.3.2. | |
| Aplazada | Crítica (9.8) | 0.49% | — | MSA Fieldserver GatewayAI | 10/12/2024 | 17/6/2026 | An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe shared secret that is static in all affected firmware versions. | |
| Aplazada | Crítica (9.8) | 0.46% | — | MSA Fieldserver GatewayAI | 10/12/2024 | 17/6/2026 | An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow them to authenticate with an internal user… | |
| Aplazada | Alta (8.2) | 0.59% | — | Heolixfy Flexible Woocommerce Checkout Field EditorAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in heoLixfy Flexible Woocommerce Checkout Field Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flexible Woocommerce Checkout Field Editor: from n/a through 2.0.1. | |
| Aplazada | Media (4.3) | 0.34% | — | Jules Colle Conditional Fields FOR Contact Form 7AI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jules Colle Conditional Fields for Contact Form 7 cf7-conditional-fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conditional Fields for Contact Form 7: from n/a through <= 2.4.1. | |
| Aplazada | Media (4.3) | 0.43% | — | Josevega Display Custom Fields IN THE Frontend Post AND User Profile FieldsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jose Vega Display custom fields in the frontend – Post and User Profile Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display custom fields in the frontend – Post and User Profile Fields: from n/a through 1.2.0. | |
| Aplazada | Media (4.3) | 0.18% | — | MSA Fieldserver GatewayAI | 29/11/2024 | 17/6/2026 | MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking. | |
| Analizada | Media (6.5) | 0.76% | — | Tychesoftwares Product Input Fields FOR Woocommerce | 26/11/2024 | 17/6/2026 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (6.9) | 0.47% | — | Django CMS Association Django CMS Attributes FieldsAI | 20/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django CMS Attributes Fields allows Stored XSS. This issue affects django CMS Attributes Fields: before 4.0. | |
| Analizada | Media (6.6) | 0.43% | — | Advancedcustomfields Advanced Custom Fields | 15/11/2024 | 17/6/2026 | The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin… | |
| Analizada | Crítica (9.8) | 1.4% | — | Vanquish User Extra Fields | 13/11/2024 | 17/6/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 16.6. This makes it possible for unauthenticated attackers to delete arbitrary files on the server,… | |
| Analizada | Alta (8.8) | 0.82% | — | Vanquish User Extra Fields | 13/11/2024 | 17/6/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields() function in all versions up to, and including, 16.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to add custom fields… |