Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.29% | — | Feedpress GeneratorAI | 7/12/2024 | 17/6/2026 | The Feedpress Generator – External RSS Frontend Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.1) | 0.45% | — | SEO Landing Page GeneratorAI | 28/11/2024 | 17/6/2026 | The SEO Landing Page Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.66.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.1) | 0.43% | — | PDF Invoices AND Packing Slips Generator FOR WoocommerceAI | 23/11/2024 | 17/6/2026 | The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (7.1) | 0.21% | — | Juan Camilo Advanced PDF GeneratorAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Juan Camilo Advanced PDF Generator advanced-pdf-generator allows Stored XSS.This issue affects Advanced PDF Generator: from n/a through <= 0.4.0. | |
| Aplazada | Media (6.5) | 0.23% | — | Nopeamedia Print PDF Generator AND PublisherAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in verkkovaraani Print PDF Generator and Publisher nopeamedia allows Stored XSS.This issue affects Print PDF Generator and Publisher: from n/a through <= 1.1.6. | |
| Aplazada | Alta (7.5) | 7.5% | 💥 Exploit | Redefiningtheweb PDF Generator Addon FOR Elementor Page BuilderAI | 16/11/2024 | 17/6/2026 | The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain… | |
| Aplazada | Crítica (10) | 0.51% | — | Bdthemes Instant Image GeneratorAI | 14/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in bdthemes Instant Image Generator ai-image allows Upload a Web Shell to a Web Server.This issue affects Instant Image Generator: from n/a through <= 1.5.2. | |
| Analizada | Baja (2.7) | 0.50% | — | Themeisle Multiple Page Generator | 12/11/2024 | 17/6/2026 | The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the mpg_upsert_project_source_block() function in all versions up to, and including, 4.0.2. This makes it possible for authenticated attackers, with editor-level access and… | |
| Aplazada | Media (5.4) | 0.33% | — | Multiple Page Generator Plugin MPGAI | 1/11/2024 | 17/6/2026 | The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access to data due to a missing capability check on several functions in all versions up to, and including, 4.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Modificada | Media (5.4) | 0.27% | — | Redefiningtheweb PDF Generator Addon FOR Elementor Page Builder | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder pdf-generator-addon-for-elementor-page-builder allows Stored XSS.This issue affects PDF Generator Addon for Elementor Page Builder: from n/a through <=… | |
| Analizada | Media (5.3) | 0.48% | — | Projectworlds Online Time Table Generator | 28/10/2024 | 17/6/2026 | A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashboard.php?info=updateprofile. The manipulation of the argument n leads to sql injection. The attack can be launched… | |
| Analizada | Media (5.3) | 0.54% | — | Projectworlds Online Time Table Generator | 28/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an unknown function of the file /timetable/admin/admindashboard.php?info=add_course. The manipulation of the argument c leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (5.4) | 0.29% | — | Bamazoo Button Generator | 25/10/2024 | 17/6/2026 | The Bamazoo – Button Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dgs shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.47% | — | Themeisle Multiple Page Generator | 20/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle MPG multiple-pages-generator-by-porthas allows SQL Injection.This issue affects MPG: from n/a through <= 3.4.7. | |
| Analizada | Crítica (9.8) | 0.62% | — | Coderevolution Echo RSS Feed Post Generator | 1/10/2024 | 17/6/2026 | The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through the echo_check_post_header_sent() function. This makes it possible for… | |
| Analizada | Media (6.1) | 0.32% | — | Contempo PDF Image Generator | 1/10/2024 | 17/6/2026 | The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Analizada | Media (6.1) | 0.40% | — | Kubiq PDF Thumbnail Generator | 13/9/2024 | 17/6/2026 | The PDF Thumbnail Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute… | |
| Analizada | Media (6.5) | 0.25% | — | Pixeljar Favicon Generator | 13/9/2024 | 17/6/2026 | The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server | |
| Analizada | Media (6.8) | 0.29% | — | Pixeljar Favicon Generator | 13/9/2024 | 17/6/2026 | The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server | |
| Analizada | Media (5.3) | 0.41% | — | Oretnom23 Simple Invoice Generator System | 7/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. The manipulation of the argument invoice_code/customer/cashier/total_amount/discount_percentage/discount_amount/tendered_amount leads to sql… | |
| Modificada | Alta (8.1) | 0.27% | — | Pixeljar Favicon Generator | 24/8/2024 | 17/6/2026 | The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the output_sub_admin_page_0 function. This makes it possible for unauthenticated attackers to delete arbitrary files on the server via a… | |
| Aplazada | Media (4.3) | 0.33% | — | Featured Image GeneratorAI | 10/7/2024 | 17/6/2026 | The Featured Image Generator plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability check on the fig_save_after_generate_image function in all versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload… | |
| Modificada | Media (5.3) | 0.53% | — | Wensolutions WP Child Theme Generator | 21/6/2024 | 17/6/2026 | The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wctg_easy_child_theme() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to create a blank child theme and activate it… | |
| Modificada | Media (5.3) | 0.35% | — | WP Dummy Content Generator Project WP Dummy Content Generator | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 2.3.0. | |
| Modificada | Alta (8.8) | 0.30% | — | AI Post Generator | Autowriter | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in AutoWriter AI Post Generator | AutoWriter.This issue affects AI Post Generator | AutoWriter: from n/a through 3.3. |