Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
200 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Wpdesk Flexible Checkout Fields | 7/6/2023 | 17/6/2026 | The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to missing authorization checks on the updateSettingsAction() function which is called via… | |
| Modificada | Alta (7.5) | 1.1% | — | Tychesoftwares Product Input Fields FOR Woocommerce | 7/6/2023 | 17/6/2026 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service. | |
| Modificada | Media (6.1) | 0.95% | 💥 Exploit | Themeisle Product Addons & Fields FOR Woocommerce | 30/5/2023 | 17/6/2026 | The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting. | |
| Modificada | Media (4.8) | 0.37% | — | Webhammer WP Custom Fields Search | 18/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Don Benjamin WP Custom Fields Search plugin <= 1.2.34 versions. | |
| Modificada | Media (4.8) | 0.46% | — | Themeisle Product Addons & Fields FOR Woocommerce | 15/5/2023 | 17/6/2026 | The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.6 does not sanitize and escape some of its setting fields, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite… | |
| Modificada | Media (6.1) | 38% | 💥 Exploit | Advancedcustomfields Advanced Custom Fields | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Woocommerce Custom Checkout Fields Editor With Drag & Drop Project Woocommerce Custom Checkout Fields Editor With Drag & Drop | 9/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Umair Saleem Woocommerce Custom Checkout Fields Editor With Drag & Drop plugin <= 0.1 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Pixelgrade Pixfields | 9/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions. | |
| Modificada | Alta (8.8) | 1.1% | — | Advancedcustomfields Advanced Custom Fields | 2/5/2023 | 17/6/2026 | The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present. | |
| Modificada | Alta (7.2) | 0.91% | — | WC Fields Factory Project WC Fields Factory | 17/4/2023 | 17/6/2026 | The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | |
| Modificada | Media (6.5) | 0.61% | — | Teclib-edition Fields | 5/4/2023 | 17/6/2026 | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check allows any authenticated user to write data to any fields container, including those to which they have no configured access. Versions 1.13.1 and 1.20.4 contain a patch… | |
| Modificada | Media (5.4) | 0.55% | — | Paidmembershipspro Custom User Profile Fields FOR User Registration | 30/1/2023 | 17/6/2026 | The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against… | |
| Modificada | Media (4.8) | 0.47% | — | Cozmoslabs Custom Post Types AND Custom Fields Creator | 16/1/2023 | 17/6/2026 | The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Crítica (9.8) | 5.0% | 💥 Exploit | Iws-geo-form-fields Project Iws-geo-form-fields | 26/12/2022 | 17/6/2026 | The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection. | |
| Modificada | Media (6.1) | 0.49% | — | Ndk-design Ndkadvancedcustomizationfields | 21/12/2022 | 9/7/2026 | A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloads injected into the "htmlNodes" parameter. | |
| Modificada | Crítica (9.1) | 0.85% | — | Ndk-design Ndkadvancedcustomizationfields | 22/11/2022 | 9/7/2026 | ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php. | |
| Modificada | Media (6.1) | 0.52% | — | Ndk-design Ndkadvancedcustomizationfields | 2/11/2022 | 9/7/2026 | ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via createPdf.php. | |
| Modificada | Alta (7.5) | 0.94% | — | Ndk-design Ndkadvancedcustomizationfields | 1/11/2022 | 9/7/2026 | A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data. | |
| Modificada | Alta (8.8) | 1.6% | — | Advancedcustomfields Advanced Custom Fields | 22/8/2022 | 17/6/2026 | The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite… | |
| Modificada | Media (4.8) | 0.61% | — | Najeebmedia Wordpress Comments Fields | 8/8/2022 | 17/6/2026 | The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (5.4) | 0.59% | — | Appfire Jira Misc Custom Fields | 7/7/2022 | 17/6/2026 | The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add Auto Indexing Rule function. | |
| Modificada | Media (6.5) | 1.5% | — | Advancedcustomfields Advanced Custom Fields | 31/3/2022 | 17/6/2026 | Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacker to view the information on the database without the access permission. | |
| Modificada | Baja (3.5) | 0.64% | — | Otrs Custom Contact Fields | 7/2/2022 | 17/6/2026 | Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affects: OTRS AG OTRSCustomContactFields 8.0.x version: 8.0.11 and prior versions. | |
| Modificada | Alta (7.2) | 1.5% | — | Acf-extended Advanced Custom Fields\ | 24/1/2022 | 17/6/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue | |
| Modificada | Media (6.5) | 1.5% | — | Advancedcustomfields Advanced Custom Fields | 13/12/2021 | 17/6/2026 | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors. |