Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

294 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.27%—Ristretto Apps Dashing MembershipsAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ristretto Apps Dashing Memberships dashing-memberships allows Reflected XSS.This issue affects Dashing Memberships: from n/a through <= 1.1.
AnalizadaAlta (7.3)0.46%—Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions9/11/202417/6/2026
The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate a…
AplazadaCrítica (9.8)0.85%—Wpmembership WP MembershipAI9/11/202417/6/2026
The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which…
AnalizadaCrítica (9.8)0.67%—Strangerstudios Paid Memberships PRO1/11/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
ModificadaMedia (6.1)0.27%—Simple-membership-plugin Simple Membership24/10/202417/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allows Phishing.This issue affects Simple Membership: from n/a through <= 4.5.3.
AnalizadaMedia (5.4)0.32%—Codeastro Membership Management System21/10/202417/6/2026
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php
AnalizadaMedia (5.4)0.30%—Codeastro Membership Management System21/10/202417/6/2026
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php.
AplazadaAlta (8.8)0.50%—Taketin TO WP MembershipAI16/10/202417/6/2026
Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affects TAKETIN To WP Membership: from n/a through <= 2.8.17.
AplazadaMedia (6.3)0.35%—Indeed Membership PROAI16/10/202417/6/2026
The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying…
AplazadaCrítica (9.8)0.69%—Wpindeed Ultimate Membership PROAI16/10/202417/6/2026
The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID.
AplazadaMedia (4.7)0.33%—Wp.insider Simple Membership After Login RedirectionAI10/10/202417/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership After Login Redirection simple-membership-after-login-redirection.This issue affects Simple Membership After Login Redirection: from n/a through <= 1.6.
AnalizadaMedia (6.1)0.39%—Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions2/10/202417/6/2026
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.8. This makes it possible for…
AnalizadaAlta (8.6)0.44%—Codeastro Membership Management System27/9/202417/6/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.
AnalizadaAlta (7.5)0.50%—Codeastro Membership Management System27/9/202417/6/2026
The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.
AnalizadaMedia (6.1)0.35%—Codeastro Membership Management System27/9/202417/6/2026
Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.
AnalizadaMedia (5.4)0.28%—Codeastro Membership Management System2/9/202417/6/2026
CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.
ModificadaCrítica (10)0.54%—Wpindeed Ultimate Membership PRO19/8/202417/6/2026
Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
ModificadaCrítica (9.8)0.55%—Wpindeed Ultimate Membership PRO19/8/202417/6/2026
Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
AplazadaAlta (7.1)0.27%—Wpindeed Ultimate Membership PROAI18/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
AplazadaMedia (6.1)0.49%—Opal MembershipAI12/8/202417/6/2026
The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
AplazadaMedia (4.3)0.59%—Opal MembershipAI12/8/202417/6/2026
The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticated attackers, with subscriber-level access and above, to view…
AnalizadaAlta (8.8)0.33%—Lopalopa Live Membership System12/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php.
AnalizadaAlta (7.6)1.1%—Lopalopa Live Membership System12/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter.
AnalizadaCrítica (9.8)1.0%—Lopalopa Live Membership System12/8/202417/6/2026
A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.
AnalizadaCrítica (9.8)1.2%—Lopalopa Live Membership System12/8/202417/6/2026
An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.
Orbitaley — Vulnerabilidades