Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.28% | — | Janekniefeldt MY Custom WidgetsAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janekniefeldt My Custom Widgets mycustomwidget allows Reflected XSS.This issue affects My Custom Widgets: from n/a through <= 2.0.5. | |
| Aplazada | Alta (7.1) | 0.27% | — | M A Vinoth Kumar Category WidgetAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Category Widget category-widget allows Reflected XSS.This issue affects Category Widget: from n/a through <= 2.0.2. | |
| Aplazada | Media (5.3) | 0.38% | — | Ctltwp Section WidgetAI | 19/5/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in ctltwp Section Widget section-widget allows Path Traversal.This issue affects Section Widget: from n/a through <= 3.3.1. | |
| Modificada | Media (5.4) | 0.26% | — | Wpfactory Back Button Widget | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back Button Widget back-button-widget allows Stored XSS.This issue affects Back Button Widget: from n/a through <= 1.6.8. | |
| Aplazada | Media (6.5) | 0.20% | — | Steve Puddick WP Notes WidgetAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Puddick WP Notes Widget wp-notes-widget allows DOM-Based XSS.This issue affects WP Notes Widget: from n/a through <= 1.0.6. | |
| Analizada | Media (4.3) | 0.18% | — | Justintadlock Widgets Reset | 15/5/2025 | 17/6/2026 | The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Media (4.8) | 0.31% | — | Pixeljar Geocache Stat BAR Widget | 15/5/2025 | 17/6/2026 | The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.31% | — | Cm-wp Social Slider Widget | 15/5/2025 | 17/6/2026 | The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (8.8) | 0.69% | — | Xylusthemes XT Event Widget FOR Social Events | 7/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events xt-facebook-events allows PHP Local File Inclusion.This issue affects XT Event Widget for Social Events: from n/a through <= 1.1.7. | |
| Aplazada | Alta (7.1) | 0.15% | — | ELI Related Posts Footer Links AND WidgetAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Eli ELI's Related Posts Footer Links and Widget spostarbust allows Stored XSS.This issue affects ELI's Related Posts Footer Links and Widget: from n/a through <= 1.2.04.20. | |
| Aplazada | Alta (7.4) | 0.21% | — | Awplife Contact Form WidgetAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Site Request Forgery.This issue affects Contact Form Widget: from n/a through <= 1.4.6. | |
| Aplazada | Media (6.5) | 0.27% | — | Wpdevart Widget CountdownAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Widget Countdown widget-countdown allows Stored XSS.This issue affects Widget Countdown: from n/a through <= 2.7.4. | |
| Aplazada | Media (6.4) | 0.24% | — | Verticalresponse Newsletter WidgetAI | 3/5/2025 | 17/6/2026 | The VerticalResponse Newsletter Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'verticalresponse' shortcode in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.9) | 0.22% | — | Stressfree Sites Business-contact-widgetAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StressFree Sites Business Contact Widget business-contact-widget allows Stored XSS.This issue affects Business Contact Widget: from n/a through <= 2.7.0. | |
| Analizada | Media (4.8) | 0.27% | — | Zephyrwest Category Posts Widget | 24/4/2025 | 17/6/2026 | The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (7.1) | 0.15% | — | Amazon Showcase Wordpress WidgetAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Aaron Forgue Amazon Showcase WordPress Plugin amazon-showcase-wordpress-widget allows Stored XSS.This issue affects Amazon Showcase WordPress Plugin: from n/a through <= 2.2. | |
| Aplazada | Baja (3.7) | 0.52% | — | WxwidgetsAI | 16/4/2025 | 17/6/2026 | In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. | |
| Aplazada | Media (6.5) | 0.35% | — | Whiletrue Most-and-least-read-posts-widgetAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in whiletrue Most And Least Read Posts Widget most-and-least-read-posts-widget allows Stored XSS.This issue affects Most And Least Read Posts Widget: from n/a through <= 2.5.20. | |
| Analizada | Media (4.8) | 0.27% | — | Patelmilap Widget FOR Social Page Feeds | 15/4/2025 | 17/6/2026 | The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (7.1) | 0.19% | — | Sudavar Codescar Radio WidgetAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sudavar Codescar Radio Widget codescar-radio-widget allows Stored XSS.This issue affects Codescar Radio Widget: from n/a through <= 0.4.2. | |
| Aplazada | Alta (7.1) | 0.21% | — | Ab-tools Flags WidgetAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ab-tools Flags Widget flags-widget allows Stored XSS.This issue affects Flags Widget: from n/a through <= 1.0.7. | |
| Aplazada | Alta (7.1) | 0.21% | — | Sodena Frescochat Live ChatAISodena Flexytalk-widgetAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sodena FrescoChat Live Chat flexytalk-widget allows Stored XSS.This issue affects FrescoChat Live Chat: from n/a through <= 3.2.6. | |
| Aplazada | Alta (7.1) | 0.23% | — | Otwthemes Widgetize Pages LightAI | 8/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Reflected XSS.This issue affects Widgetize Pages Light: from n/a through <= 3.0. | |
| Aplazada | Media (4.3) | 0.19% | — | Freetobook Responsive WidgetAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in freetobook Freetobook Responsive Widget freetobook-responsive-widget allows Cross Site Request Forgery.This issue affects Freetobook Responsive Widget: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.38% | — | Otwthemes Widget Manager LightAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in OTWthemes Widget Manager Light widget-manager-light allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Widget Manager Light: from n/a through <= 1.18. |