Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

250 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.88%—Insights From Google Pagespeed Project Insights From Google Pagespeed4/4/202217/6/2026
The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting
ModificadaMedia (4.8)0.56%—Ampforwp Accelerated Mobile Pages18/3/202217/6/2026
Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).
ModificadaMedia (4.8)0.56%—Ampforwp Accelerated Mobile Pages18/3/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.
ModificadaMedia (6.5)1.1%—Finastra Ssr-pages1/3/202217/6/2026
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the `svg` property as an argument to the `build(MessagePageOptions)` function. While there is no known workaround at this time, there is a…
ModificadaMedia (6.1)0.87%—Finastra Ssr-pages1/3/202217/6/2026
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.5, a cross site scripting (XSS) issue can occur when providing untrusted input to the `redirect.link` property as an argument to the `build(MessagePageOptions)` function. While there is no known workaround at…
ModificadaMedia (4.8)0.65%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV28/2/202217/6/2026
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues
ModificadaMedia (5.4)0.60%—Wpeka Wplegalpages7/2/202217/6/2026
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them. Furthermore, due to the lack of…
ModificadaMedia (4.3)0.94%—Insert Pages Project Insert Pages17/11/202117/6/2026
The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcode. Password protected posts/pages are not affected by such issue.
ModificadaMedia (5.4)0.62%—Insert Pages Project Insert Pages17/11/202117/6/2026
The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site Scripting attacks by storing the payload/s in another post's custom fields.
ModificadaAlta (8.8)1.5%—IBM Openpages With Watson31/8/202117/6/2026
IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary code on the system. IBM X-Force ID: 207633.
ModificadaMedia (6.1)0.83%—Kylephillips Nested Pages30/8/202117/6/2026
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.
ModificadaAlta (8.1)0.49%—Kylephillips Nested Pages30/8/202117/6/2026
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.
ModificadaMedia (4.3)0.98%—IBM Openpages GRC Platform11/5/202117/6/2026
IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182907.
ModificadaMedia (5.4)0.50%—IBM Openpages GRC Platform11/5/202117/6/2026
IBM OpenPages GRC Platform 8.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182906.
ModificadaMedia (4.8)2.0%💥 Exploit4homepages 4images22/3/202117/6/2026
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.
ModificadaMedia (4.8)0.59%—4homepages 4images26/1/202117/6/2026
4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. Each time a user visits that URL, the XSS triggers and the attacker can be able to steal the cookie according to the…
ModificadaMedia (6.1)0.90%—SAP Netweaver AS Abap Business Server Pages9/9/202017/6/2026
SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacker to send polluted URL to the victim, when the victim clicks on this URL, the attacker can read, modify the information available in the victim�s browser leading to…
ModificadaMedia (6.1)0.65%—SAP Netweaver AS Abap Business Server Pages10/6/202017/6/2026
SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
ModificadaMedia (6.1)0.80%—SAP Netweaver AS Abap Business Server Pages24/4/202017/6/2026
SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulnerable to reflected Cross-Site Scripting (XSS) via different URL parameters as it does not sufficiently encode user controlled inputs.
ModificadaMedia (6.1)0.65%—SAP Netweaver AS Abap Business Server Pages14/4/202017/6/2026
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
ModificadaMedia (6.1)1.6%—SAP Netweaver AS Abap Business Server Pages14/4/202017/6/2026
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.
ModificadaMedia (6.1)0.65%—SAP Netweaver AS Abap Business Server Pages14/4/202017/6/2026
SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
ModificadaMedia (6.1)0.77%—SAP Netweaver AS Abap Business Server Pages10/3/202017/6/2026
SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or modify displayed content and/or steal…
ModificadaCrítica (9.8)5.3%—Handsomeweb SOS Webpages28/1/202017/6/2026
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.
ModificadaCrítica (9.8)1.8%—Impresspages CMS22/1/202016/6/2026
ImpressPages CMS v1.0.12 has Unspecified Remote Code Execution (fixed in v1.0.13)
Orbitaley — Vulnerabilidades