Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
289 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.33% | — | Ninjateam Click TO Chat | 18/10/2024 | 17/6/2026 | The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsaio_snapchat shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Modificada | Media (5.4) | 0.55% | — | Ninjateam Click TO Chat | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.3. | |
| Modificada | Alta (8.5) | 0.42% | — | Wpmanageninja Fluent Support | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Fluent Support fluent-support allows SQL Injection.This issue affects Fluent Support: from n/a through <= 1.8.0. | |
| Analizada | Alta (7.2) | 0.64% | — | Nintechnet Ninjafirewall | 16/10/2024 | 17/6/2026 | The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits if vulnerable software is present… | |
| Modificada | Crítica (9.8) | 0.60% | — | Ninjateam Multi Step FOR Contact Form 7 | 11/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ninja Team Multi Step for Contact Form cf7-multi-step allows SQL Injection.This issue affects Multi Step for Contact Form: from n/a through <= 2.7.7. | |
| Analizada | Media (6.1) | 0.29% | — | Ninjaforms Ninja Forms | 25/9/2024 | 17/6/2026 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (4.8) | 0.31% | — | Ninjaforms Ninja Forms | 18/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.11. | |
| Analizada | Media (4.8) | 0.36% | — | Ninjateam Header Footer Custom Code | 13/9/2024 | 17/6/2026 | The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (4.8) | 0.34% | — | Ninjateam Header Footer Custom Code | 13/9/2024 | 17/6/2026 | The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (6.1) | 0.43% | — | Ninjaforms Ninja Forms File Uploads | 7/9/2024 | 17/6/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (6.1) | 0.70% | 💥 Exploit | Ninjaforms Ninja Forms | 2/9/2024 | 17/6/2026 | The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Media (5.4) | 0.39% | — | Wpmanageninja Ninja Tables | 27/8/2024 | 17/6/2026 | The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and… | |
| Modificada | Alta (8.8) | 0.20% | — | Ninjaforms Ninja Forms | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6. | |
| Analizada | Alta (8.8) | 0.62% | — | Ninjateam Filester | 3/8/2024 | 17/6/2026 | The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' function in all versions up to, and including, 1.8.2. This makes it possible for authenticated attackers, with a role that has been granted… | |
| Modificada | Media (5.4) | 0.24% | — | Ninjabeaveraddon Ninja Beaver Add-ons FOR Beaver Builder | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ninja Team Ninja Beaver Add-ons for Beaver Builder allows Stored XSS.This issue affects Ninja Beaver Add-ons for Beaver Builder: from n/a through 2.4.5. | |
| Aplazada | Media (5.3) | 0.44% | — | Ninjateam Filebird Document LibraryAI | 10/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FileBird Document Library.This issue affects FileBird Document Library: from n/a through 2.0.6. | |
| Modificada | Crítica (9.8) | 0.47% | — | Ninjaforms Ninja Forms | 9/7/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4. | |
| Modificada | Media (4.8) | 0.37% | — | Ninjateam WP Chat APP | 27/6/2024 | 17/6/2026 | The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. | |
| Modificada | Alta (8.8) | 0.54% | — | Ninjaforms Ninja Forms | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25. | |
| Analizada | Crítica (9.8) | 0.50% | — | Ninjaforms Ninja Forms | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25. | |
| Modificada | Media (5.3) | 0.33% | — | Wpmanageninja Ninja Tables | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.5. | |
| Modificada | Media (4.3) | 0.33% | — | Wpmanageninja Ninja Tables | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.6. | |
| Modificada | Media (5.4) | 0.28% | — | Ninjateam Gdpr Ccpa Compliance & Cookie Consent Banner | 7/6/2024 | 17/6/2026 | The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions named ajaxUpdateSettings() in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (7.5) | 0.78% | 💥 PoC | Ninjaframework Ninja | 6/6/2024 | 17/6/2026 | The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information. | |
| Analizada | Media (4.9) | 0.24% | — | Wpmanageninja Ninja Tables | 3/6/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.9. |