Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | 💥 PoC | Supsystic Popup | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19. | |
| Analizada | Media (6.1) | 0.39% | — | Ivanweb Popup4phone | 17/5/2024 | 17/6/2026 | The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (6.1) | 0.68% | 💥 Exploit | Ivanweb Popup4phone | 17/5/2024 | 17/6/2026 | The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins. | |
| Aplazada | Media (6.5) | 0.26% | — | Ghozylab Popup BuilderAI | 17/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GhozyLab, Inc. Popup Builder allows Stored XSS.This issue affects Popup Builder: from n/a through 1.1.29. | |
| Aplazada | Media (6.5) | 0.25% | — | Felixmoira Popup More PopupsAI | 17/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Felix Moira Popup More Popups allows Stored XSS.This issue affects Popup More Popups: from n/a through 2.3.1. | |
| Analizada | Media (4.8) | 0.37% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.35% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack | |
| Analizada | Media (6.9) | 0.25% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack | |
| Analizada | Media (6.1) | 0.39% | — | Mndpsingh287 Newsletter Popup | 16/5/2024 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins | |
| Aplazada | Alta (7.1) | 0.18% | — | Popup BOX Team Popup BOXAI | 6/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Popup Box Team Popup box allows Cross-Site Scripting (XSS).This issue affects Popup box: from n/a through 4.1.2. | |
| Aplazada | Media (5.9) | 0.36% | — | Maxim K Ajax Login AND Registration Modal Popup Inline FormAI | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxim K AJAX Login and Registration modal popup + inline form allows Stored XSS.This issue affects AJAX Login and Registration modal popup + inline form: from n/a through 2.23. | |
| Aplazada | Media (5.3) | 0.62% | — | AYS Popup BOX Popup BOXAI | 2/5/2024 | 17/6/2026 | The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_pb_create_author AJAX action in all versions up to, and including, 4.3.6. This makes it possible for unauthenticated attackers to enumerate all emails registered on… | |
| Aplazada | Media (5.9) | 0.38% | — | Mrdigital Simple Image PopupAI | 2/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple Image Popup allows Stored XSS.This issue affects Simple Image Popup: from n/a through 2.4.0. | |
| Analizada | Media (4.3) | 0.28% | — | Wow-company Popup BOX | 2/5/2024 | 17/6/2026 | The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks | |
| Aplazada | Media (4.3) | 0.20% | — | Optinmonster Popup BuilderAI | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OptinMonster Popup Builder Team OptinMonster.This issue affects OptinMonster: from n/a through 2.15.3. | |
| Modificada | Media (4.8) | 0.36% | — | Accessally Popupally | 26/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1. | |
| Aplazada | Media (5.3) | 0.42% | — | Essentialplugin Popup AnythingAI | 18/4/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Popup Anything.This issue affects Popup Anything: from n/a through 2.8. | |
| Modificada | Media (4.3) | 0.36% | — | Supsystic Popup | 15/4/2024 | 17/6/2026 | Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27. | |
| Aplazada | Media (4.3) | 0.20% | — | Nudgify Social Proof Sales Popup FomoAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nudgify Nudgify Social Proof, Sales Popup & FOMO.This issue affects Nudgify Social Proof, Sales Popup & FOMO: from n/a through 1.3.3. | |
| Aplazada | Media (5.9) | 0.32% | — | Ays-pro Popup Like BOXAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup LikeBox Team Popup Like box allows Stored XSS.This issue affects Popup Like box: from n/a through 3.7.2. | |
| Modificada | Media (5.4) | 0.34% | — | Code-atlantic Popup Maker | 9/4/2024 | 17/6/2026 | The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.18.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.89% | — | AWL Modal Popup BOXAI | 4/4/2024 | 17/6/2026 | The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.2 via deserialization of untrusted input in the awl_modal_popup_box_shortcode function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.4) | 0.20% | — | Festi-team Popup Cart Lite FOR WoocommerceAI | 31/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Festi-Team Popup Cart Lite for WooCommerce.This issue affects Popup Cart Lite for WooCommerce: from n/a through 1.1. | |
| Aplazada | Media (5.4) | 0.30% | — | Brave Popup BuilderAI | 29/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.6.5. | |
| Aplazada | Media (6.5) | 0.36% | — | Looking Forward Software Incorporated Popup BuilderAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Looking Forward Software Incorporated. Popup Builder allows Stored XSS.This issue affects Popup Builder: from n/a through 4.2.6. |