Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | — | Commentapp.stetsonwood Project Commentapp.stetsonwood | 7/6/2018 | 17/6/2026 | commentapp.stetsonwood is an http server. commentapp.stetsonwood is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (8.8) | 1.6% | — | Disable Comments Project | 19/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that enable comments via a request to the disable_comments_settings page to wp-admin/options-general.php. | |
| Modificada | Alta (8.8) | 0.91% | — | Subscribe TO Comments Reloaded Project Subscribe TO Comments Reloaded | 19/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the… | |
| Modificada | Crítica (9.1) | 8.6% | — | Contussupport Contus-video-comments | 6/10/2016 | 17/6/2026 | Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin | |
| Modificada | Media (6.8) | 1.0% | — | Wpcommenttwit Project Wpcommenttwit | 19/12/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the wpCommentTwit plugin 0.5 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) username or (2) password parameter in the wpCommentTwit.php… | |
| Modificada | Media (6.8) | 4.9% | 💥 Exploit | Disqus Comment System | 19/8/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) disqus_replace, (2) disqus_public_key, or (3)… | |
| Modificada | Media (6.8) | 2.7% | 💥 Exploit | Disqus Comment System | 19/8/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) activate or (2) deactivate the plugin via the active parameter to wp-admin/edit-comments.php, (3) import comments… | |
| Modificada | Media (4.3) | 6.1% | 💥 Exploit | Disqus Comment System | 19/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Verification Code FOR Comments Project Verification Code FOR Comments | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm parameter. | |
| Modificada | Media (6.8) | 2.6% | 💥 Exploit | Featured Comments Plugin Project Featured Comments | 16/6/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that change the (1) buried or (2) featured status of a comment via a request to wp-admin/admin-ajax.php. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Commentluv | 3/3/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Joomla COM Jvcomment | 26/1/2014 | 17/6/2026 | SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a comment.like action to index.php. | |
| Modificada | Media (4.3) | 2.0% | — | Wearegumball Comment-attachment | 3/10/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Comment Attachment plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Attachment field title." | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Vanillaforums Latestcomment | 23/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or HTML via the discussion title. | |
| Modificada | Media (6.8) | 0.78% | — | David Stosik Comment Moderation | 21/6/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Comment Moderation module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to hijack the authentication of administrators for requests that publish comments. | |
| Modificada | Media (4.3) | 2.1% | — | Mg12 Wp-recentcomments | 14/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging. | |
| Modificada | Alta (7.5) | 2.0% | — | Mg12 Wp-recentcomments | 14/2/2012 | 16/6/2026 | SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Joomlatune COM Jcomments | 23/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Raphael Zschorsch Commentsbe | 7/10/2011 | 16/6/2026 | SQL injection vulnerability in the Commenting system Backend Module (commentsbe) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Jxtended Comments | 9/12/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the JXtended Comments component before 1.3.1 for Joomla allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Rsjoomla COM Rscomments | 25/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | M0r0n COM Mscomment | 25/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Zimbllc COM Zimbcomment | 29/4/2010 | 16/6/2026 | Directory traversal vulnerability in the ZiMB Comment (com_zimbcomment) component 0.8.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Media (5) | 16% | 💥 Exploit | Joomlamart COM Jacomment | 29/4/2010 | 16/6/2026 | Directory traversal vulnerability in the JA Comment (com_jacomment) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. | |
| Modificada | Media (4.3) | 1.1% | — | Alkacon Oamp Comments | 26/3/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unspecified vectors. |