Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
378 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.5) | 0.33% | — | Buttonizer Call / Chat / Contact Button | 23/5/2024 | 17/6/2026 | The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (4.4) | 0.27% | — | Paypal PAY NOW BUY NOW Donation AND Cart Buttons ShortcodeAI | 23/5/2024 | 17/6/2026 | The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.5) | 0.57% | — | Idiom Easy Social Share ButtonsAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appscreo Easy Social Share Buttons allows PHP Local File Inclusion.This issue affects Easy Social Share Buttons: from n/a through 9.4. | |
| Aplazada | Baja (2.8) | 0.18% | — | Knowbe4 Phish Alert Button FOR OutlookAIKnowbe4 Second Chance ClientAIKnowbe4 PIQ ClientAI | 7/5/2024 | 17/6/2026 | A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifically within its configuration management functionalities. This vulnerability allows a regular user to modify the application's configuration file to redirect update checks to an arbitrary server, which… | |
| Aplazada | Media (6) | 0.37% | — | Knowbe4 Phish Alert ButtonAIKnowbe4 Second Chance ClientAIKnowbe4 PIQ ClientAI | 7/5/2024 | 17/6/2026 | A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which could allow an attacker to remotely execute arbitrary code on the host machine. The vulnerability arises from the application's failure to securely verify the authenticity and integrity of the… | |
| Modificada | Media (6.1) | 0.33% | — | Codebard's Patron Button AND Widgets FOR Patreon | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon allows Reflected XSS.This issue affects CodeBard's Patron Button and Widgets for Patreon: from n/a through 2.2.0. | |
| Analizada | Alta (7.5) | 0.28% | — | Wow-company Sticky Buttons | 2/5/2024 | 17/6/2026 | The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks | |
| Modificada | Alta (8.8) | 0.35% | — | Wow-company WOW Skype Buttons | 2/5/2024 | 17/6/2026 | The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks | |
| Analizada | Baja (3.4) | 0.23% | — | Wow-company Button Generator | 2/5/2024 | 17/6/2026 | The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack | |
| Analizada | Media (4.3) | 0.67% | — | Callnowbutton Call NOW Button | 26/4/2024 | 17/6/2026 | The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (6.1) | 0.41% | — | Bigbluebutton Greenlight | 25/4/2024 | 17/6/2026 | Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue. | |
| Analizada | Media (6.1) | 0.36% | — | Bigbluebutton Greenlight | 25/4/2024 | 17/6/2026 | Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue. | |
| Aplazada | Media (5.9) | 0.34% | — | Coupon & Discount Code Reveal ButtonAI | 24/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coupon & Discount Code Reveal Button allows Stored XSS.This issue affects Coupon & Discount Code Reveal Button: from n/a through 1.2.5. | |
| Analizada | Media (5.9) | 0.40% | — | Inisev Social Media Share Buttons & Social Sharing Icons | 17/4/2024 | 17/6/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Modificada | Media (4.8) | 0.34% | — | Mosswebworks MWW Disclaimer Buttons | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moss Web Works MWW Disclaimer Buttons allows Stored XSS.This issue affects MWW Disclaimer Buttons: from n/a through 3.0.2. | |
| Analizada | Media (4.8) | 0.19% | — | Robbychen Simple Buttons Creator | 15/4/2024 | 17/6/2026 | The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | |
| Analizada | Media (6.1) | 0.24% | — | Robbychen Simple Buttons Creator | 15/4/2024 | 17/6/2026 | The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored… | |
| Aplazada | Media (6.4) | 0.34% | — | Global Elementor ButtonsAI | 9/4/2024 | 17/6/2026 | The Global Elementor Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link URL in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Aplazada | Alta (7.1) | 0.18% | — | Toastie Studio Woocommerce Social Media Share ButtonsAI | 2/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Toastie Studio Woocommerce Social Media Share Buttons allows Stored XSS.This issue affects Woocommerce Social Media Share Buttons: from n/a through 1.3.0. | |
| Aplazada | Alta (8.8) | 0.89% | — | Webdzier ButtonAI | 29/3/2024 | 17/6/2026 | The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via deserialization of untrusted input in the button_shortcode function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP… | |
| Aplazada | Alta (7.1) | 0.35% | — | Idiom Easy Social Share ButtonsAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Appscreo Easy Social Share Buttons allows Reflected XSS.This issue affects Easy Social Share Buttons: from n/a through 9.4. | |
| Modificada | Alta (8.8) | 0.67% | — | Sygnoos Social Media Share Buttons | 20/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0. | |
| Aplazada | Media (6.4) | 0.40% | — | Standout Color Boxes AND ButtonsAI | 20/3/2024 | 17/6/2026 | The Standout Color Boxes and Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'color-button' shortcode in all versions up to, and including, 0.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.1) | 0.41% | — | Otwthemes Buttons Shortcode AND Widget | 18/3/2024 | 17/6/2026 | The Buttons Shortcode and Widget WordPress plugin through 1.16 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 0.77% | — | Sygnoos Social Media Share Buttons | 16/3/2024 | 17/6/2026 | The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserialization of untrusted input through the attachmentUrl parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP… |