Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
3372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Cozmoslabs TranslatepressAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Stitch ExpressAI | 19/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. | |
| Aplazada | Alta (7.2) | 0.39% | — | Cozmoslabs TranslatepressAI | 19/8/2026 | 20/8/2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including 3.2.5. The special gettext markers '#!trpst#' and '#!trpen#' are unconditionally rewritten to '<' and '>' by translate_page() in… | |
| Aplazada | Baja (2.7) | 0.30% | — | Expressivequiz Quiz AND Survey MasterAI | 19/8/2026 | 26/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient… | |
| Aplazada | Media (5.9) | 0.24% | — | Publishpress SeriesAI | 18/8/2026 | 20/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from n/a through 2.17.0. | |
| Aplazada | Alta (8.8) | 0.20% | — | Devitems Hashbar Wordpress Notification BARAI | 18/8/2026 | 20/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0. | |
| Aplazada | Alta (8.8) | 0.52% | — | TaxopressAI | 18/8/2026 | 20/8/2026 | Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0. | |
| Aplazada | Alta (8.1) | 0.47% | — | Motopress Restaurant MenuAI | 18/8/2026 | 20/8/2026 | Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Social Login AND RegisterAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. | |
| Aplazada | Crítica (10) | 0.86% | — | Wpcompress WP CompressAI | 18/8/2026 | 20/8/2026 | Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | ThumbpressAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. | |
| Pendiente de análisis | Alta (8.8) | 1.9% | 💥 PoC | WordpressAI | 17/8/2026 | 3/9/2026 | WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has… | |
| Aplazada | Media (6.5) | 0.24% | — | Wpcompress WP CompressAI | 16/8/2026 | 20/8/2026 | The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or incorrect nonce validation on the (top-level template code) function. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (6.6) | 0.69% | — | Weavertheme Turnkey BbpressAI | 16/8/2026 | 20/8/2026 | The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function (reached through the wvrbbp_save_restore() settings-restore handler). The function reads the… | |
| Aplazada | Media (5.4) | 0.52% | — | ProfilepressAI | 16/8/2026 | 20/8/2026 | The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.19. This is due to the software allowing users to execute an action that does not… | |
| Aplazada | Media (6.4) | 0.42% | — | Expresstech Quiz Survey MasterAI | 16/8/2026 | 20/8/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (8.6) | 1.1% | — | ImpresscmsAI | 14/8/2026 | 26/8/2026 | ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded content via undoHtmlSpecialChars() before… | |
| Aplazada | Alta (7.1) | 0.26% | — | Snstheme Samex Clean Minimal Shop Woocommerce Wordpress ThemeAISnstheme M ANH Fashion Woocommerce Wordpress ThemeAI | 13/8/2026 | 14/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress… | |
| Aplazada | Crítica (9.3) | 0.40% | — | RealpressAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. | |
| Aplazada | Media (6) | 0.21% | — | ReactpressAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. | |
| Aplazada | Media (5.3) | 0.47% | — | Prevent Direct Access Protect Wordpress FilesAI | 13/8/2026 | 14/8/2026 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without… | |
| Aplazada | Alta (8.8) | 0.47% | — | Cedar Policy Authorization FOR ExpressjsAIExpressAI | 13/8/2026 | 9/9/2026 | @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue where, under certain… | |
| Aplazada | Alta (8.4) | 0.40% | — | Fujitsu Research OnecompressionAI | 12/8/2026 | 24/9/2026 | Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking… | |
| Aplazada | Alta (7.1) | 0.29% | — | Blubrry PowerpressAI | 12/8/2026 | 26/8/2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services. | |
| Aplazada | Media (6.5) | 0.37% | — | Thimpress LearnpressAI | 12/8/2026 | 26/8/2026 | The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson content, allowing any authenticated user such as a subscriber to obtain material from paid courses they have not enrolled in. |