Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.6) | 0.29% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function | |
| Modificada | Media (5.3) | 0.32% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function | |
| Aplazada | Media (4.3) | 0.20% | — | LLM Hubspot Blog ImportAI | 24/10/2025 | 30/9/2026 | The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_save_blogs' AJAX endpoint in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.13% | — | Johnh10 Video Blogster LiteAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Stored XSS.This issue affects Video Blogster Lite: from n/a through <= 1.2. | |
| Aplazada | Media (6.5) | 0.22% | — | Crocoblock JetblogAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows Reflected XSS.This issue affects JetBlog: from n/a through <= 2.4.4. | |
| Aplazada | Media (6.5) | 0.22% | — | Crocoblock JetblogAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows Stored XSS.This issue affects JetBlog: from n/a through <= 2.4.4.1. | |
| Analizada | Media (5.3) | 0.26% | — | Oracle Weblogic Server | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.… | |
| Analizada | Alta (7.5) | 0.40% | — | Oracle Weblogic Server | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle WebLogic Server. Successful attacks… | |
| Aplazada | Crítica (9.8) | 0.37% | — | Thrivex Blogging FrameworkAI | 29/9/2025 | 17/6/2026 | An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint. | |
| Aplazada | Media (5.4) | 0.28% | — | Solwininfotech Blog DesignerAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in solwininfotech Blog Designer blog-designer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blog Designer: from n/a through <= 3.1.8. | |
| Aplazada | Media (5.5) | 0.19% | — | Butlerblog Wp-membersAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chad Butler WP-Members wp-members allows Stored XSS.This issue affects WP-Members: from n/a through <= 3.5.4.2. | |
| Aplazada | Media (4.3) | 0.17% | — | Travelmap-blogAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in TravelMap Travel Map travelmap-blog allows Cross Site Request Forgery.This issue affects Travel Map: from n/a through <= 1.0.3. | |
| Analizada | Alta (7.5) | 0.40% | — | Zhyd Oneblog | 16/9/2025 | 17/6/2026 | The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability. | |
| Aplazada | Baja (2.1) | 0.44% | — | H3blogAI | 15/9/2025 | 17/6/2026 | A vulnerability has been found in pojoin h3blog up to 5bf704425ebc11f4c24da51f32f36bb17ae20489. Affected by this issue is the function ppt_log of the file /login of the component HTTP Header Handler. Such manipulation of the argument X-Forwarded-For leads to cross site scripting. The attack may be performed from… | |
| Aplazada | Media (6.1) | 0.15% | — | Ultimate BlogrollAI | 12/9/2025 | 17/6/2026 | The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged… | |
| Aplazada | Media (4.3) | 0.13% | — | Blog Designer FOR ElementorAI | 11/9/2025 | 17/6/2026 | The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.1.7. This is due to missing or incorrect nonce validation on the bdfe_install_activate_rswpbs_only function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.5) | 0.51% | — | Solwin Blog Designer PROAI | 9/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Designer PRO: from n/a through <= 3.4.7. | |
| Aplazada | Alta (7.1) | 0.23% | — | Solwin Blog Designer PROAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Designer PRO: from n/a through <= 3.4.7. | |
| Aplazada | Media (5) | 0.29% | — | Butlerblog Wp-membersAI | 9/9/2025 | 17/6/2026 | The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Aplazada | Alta (8.7) | 0.58% | — | Xwiki BlogAI | 8/9/2025 | 17/6/2026 | The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Prior to version 9.14, the blog application in XWiki allowed remote code execution for any user who has edit right on any page. Normally, these are all logged-in users as they can edit their own user profile. For an exploit,… | |
| Analizada | Baja (1.9) | 0.31% | — | Fabian Responsive Blog Site | 4/9/2025 | 17/6/2026 | A weakness has been identified in code-projects Responsive Blog Site 1.0. This affects an unknown function of the file blogs_view.php. Executing manipulation of the argument product_code/gen_name/product_name/supplier can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Alta (8.1) | 0.47% | — | Solwin Blog Designer PROAI | 31/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Designer PRO: from n/a through <= 3.4.7. | |
| Analizada | Baja (2.1) | 0.36% | — | Mtons Mblog | 29/8/2025 | 17/6/2026 | A weakness has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/role/list. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. | |
| Aplazada | Alta (8.1) | 0.54% | — | Wpinterface BlogmarksAI | 28/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpinterface BlogMarks blogmarks allows PHP Local File Inclusion.This issue affects BlogMarks: from n/a through <= 1.0.8. | |
| Analizada | Baja (2.1) | 0.41% | — | Mtons Mblog | 26/8/2025 | 17/6/2026 | A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin Panel. Performing manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be… |