Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.26% | — | Rtowebsites Dynamic ConditionsAI | 4/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtowebsites Dynamic Conditions dynamicconditions allows Stored XSS.This issue affects Dynamic Conditions: from n/a through <= 1.7.4. | |
| Analizada | Media (6.5) | 0.31% | — | Elementor Website Builder | 30/1/2025 | 17/6/2026 | The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 via the 'elementor-template' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including… | |
| Aplazada | Alta (8.5) | 0.37% | — | Rtowebsites DynamictagsAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in rtowebsites DynamicTags dynamictags allows Blind SQL Injection.This issue affects DynamicTags: from n/a through <= 1.4.0. | |
| Analizada | Media (5.4) | 0.32% | — | Elementor Website Builder | 21/12/2024 | 17/6/2026 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (6.1) | 0.41% | — | Website Toolbox CommunityAI | 12/12/2024 | 17/6/2026 | The Website Toolbox Community plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘websitetoolbox_username’ parameter in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Media (5.4) | 0.48% | — | Northernbeacheswebsites Ideapush | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson IdeaPush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through n/a. | |
| Aplazada | Media (4.3) | 0.37% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.31. | |
| Aplazada | Media (6.5) | 0.55% | — | Onewebsite WP RepostAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in OneWebsite WP Repost allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Repost: from n/a through 0.1. | |
| Analizada | Media (4.3) | 0.34% | — | Northernbeacheswebsites Ideapush | 3/12/2024 | 17/6/2026 | The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions up to, and including, 8.71. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete terms… | |
| Analizada | Media (5.4) | 0.37% | — | Elementor Website Builder | 26/11/2024 | 17/6/2026 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.23% | — | Wpwebsitecreator WP Website CreatorAIWpformsAIFormidableAINinjaAI+2 | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpwebsitecreator Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera wp-website-creator allows Stored XSS.This issue affects Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera:… | |
| Aplazada | Alta (8.8) | 0.32% | — | Egebilgi Website TemplateAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egebilgi Software Website Template allows SQL Injection. This issue affects Website Template: before 29.04.2024. | |
| Aplazada | Alta (8.5) | 0.40% | — | Maksym Marko Website Price CalculatorAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Maksym Marko Website price calculator price-calculator-to-your-website allows SQL Injection.This issue affects Website price calculator: from n/a through <= 4.1. | |
| Analizada | Crítica (9.8) | 1.5% | 💥 PoC | Websiteinwp Blogpoet | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WebsiteinWP Blogpoet allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blogpoet: from n/a through 1.0.3. | |
| Aplazada | Media (4.3) | 0.40% | — | Northernbeacheswebsites WP GotowebinarAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP GoToWebinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP GoToWebinar: from n/a through 15.6. | |
| Modificada | Alta (8.8) | 0.21% | — | Northernbeacheswebsites Ideapush | 20/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Northern Beaches Websites IdeaPush ideapush allows Cross Site Request Forgery.This issue affects IdeaPush: from n/a through <= 8.69. | |
| Modificada | Crítica (9.8) | 0.55% | — | Paxman Product Website Showcase | 20/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in paxmanpwnz Product Website Showcase product-websites-showcase allows Upload a Web Shell to a Web Server.This issue affects Product Website Showcase: from n/a through <= 1.0. | |
| Analizada | Media (4.3) | 0.40% | — | Elementor Website Builder | 15/10/2024 | 17/6/2026 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either… | |
| Modificada | Media (4.8) | 0.28% | — | Northernbeacheswebsites Ideapush | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches Websites IdeaPush ideapush allows Stored XSS.This issue affects IdeaPush: from n/a through <= 8.66. | |
| Aplazada | Alta (7.5) | 0.56% | — | Istmoplugins Instant-chat-floating-button-for-wordpress-websitesAI | 5/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Instant Chat Floating Button for WordPress Websites instant-chat-wp allows PHP Local File Inclusion.This issue affects Instant Chat Floating Button for WordPress Websites: from n/a through <= 1.0.5. | |
| Aplazada | Crítica (9.2) | 0.39% | — | RSM Design Website TemplateAI | 27/9/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RSM Design Website Template allows SQL Injection. This issue affects Website Template: before 1.2. | |
| Analizada | Alta (7.2) | 1.00% | — | Prisna Google Website Translator | 25/9/2024 | 17/6/2026 | The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via deserialization of untrusted input from the 'prisna_import' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Analizada | Media (5.4) | 0.39% | — | Elementor Website Builder | 11/9/2024 | 17/6/2026 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Alta (8.8) | 0.54% | — | Oretnom23 Simple Forum Website | 6/9/2024 | 17/6/2026 | Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=. | |
| Analizada | Media (6.9) | 0.74% | — | Donbermoy E-commerce Website | 27/8/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester E-Commerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file /Admin/registration.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… |