Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

3372 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Cozmoslabs TranslatepressAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
AplazadaAlta (7.5)0.35%—Stitch ExpressAI19/8/202620/8/2026
Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
AplazadaAlta (7.2)0.39%—Cozmoslabs TranslatepressAI19/8/202620/8/2026
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including 3.2.5. The special gettext markers '#!trpst#' and '#!trpen#' are unconditionally rewritten to '<' and '>' by translate_page() in…
AplazadaBaja (2.7)0.30%—Expressivequiz Quiz AND Survey MasterAI19/8/202626/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient…
AplazadaMedia (5.9)0.24%—Publishpress SeriesAI18/8/202620/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from n/a through 2.17.0.
AplazadaAlta (8.8)0.20%—Devitems Hashbar Wordpress Notification BARAI18/8/202620/8/2026
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
AplazadaAlta (8.8)0.52%—TaxopressAI18/8/202620/8/2026
Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.
AplazadaAlta (8.1)0.47%—Motopress Restaurant MenuAI18/8/202620/8/2026
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
AplazadaAlta (7.1)0.25%—Wordpress Social Login AND RegisterAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
AplazadaCrítica (10)0.86%—Wpcompress WP CompressAI18/8/202620/8/2026
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
AplazadaAlta (7.5)0.39%—ThumbpressAI18/8/202620/8/2026
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
Pendiente de análisisAlta (8.8)1.9%💥 PoCWordpressAI17/8/20263/9/2026
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has…
AplazadaMedia (6.5)0.24%—Wpcompress WP CompressAI16/8/202620/8/2026
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or incorrect nonce validation on the (top-level template code) function. This makes it possible for unauthenticated attackers…
AplazadaMedia (6.6)0.69%—Weavertheme Turnkey BbpressAI16/8/202620/8/2026
The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function (reached through the wvrbbp_save_restore() settings-restore handler). The function reads the…
AplazadaMedia (5.4)0.52%—ProfilepressAI16/8/202620/8/2026
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.19. This is due to the software allowing users to execute an action that does not…
AplazadaMedia (6.4)0.42%—Expresstech Quiz Survey MasterAI16/8/202620/8/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaAlta (8.6)1.1%—ImpresscmsAI14/8/202626/8/2026
ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded content via undoHtmlSpecialChars() before…
AplazadaAlta (7.1)0.26%—Snstheme Samex Clean Minimal Shop Woocommerce Wordpress ThemeAISnstheme M ANH Fashion Woocommerce Wordpress ThemeAI13/8/202614/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress…
AplazadaCrítica (9.3)0.40%—RealpressAI13/8/202614/8/2026
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
AplazadaMedia (6)0.21%—ReactpressAI13/8/202614/8/2026
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
AplazadaMedia (5.3)0.47%—Prevent Direct Access Protect Wordpress FilesAI13/8/202614/8/2026
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without…
AplazadaAlta (8.8)0.47%—Cedar Policy Authorization FOR ExpressjsAIExpressAI13/8/20269/9/2026
@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue where, under certain…
AplazadaAlta (8.4)0.40%—Fujitsu Research OnecompressionAI12/8/202624/9/2026
Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking…
AplazadaAlta (7.1)0.29%—Blubrry PowerpressAI12/8/202626/8/2026
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.
AplazadaMedia (6.5)0.37%—Thimpress LearnpressAI12/8/202626/8/2026
The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson content, allowing any authenticated user such as a subscriber to obtain material from paid courses they have not enrolled in.