Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.64% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 5/4/2023 | 17/6/2026 | The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to perform a… | |
| Modificada | Alta (8.8) | 1.1% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 12/12/2022 | 17/6/2026 | The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload. | |
| Modificada | Crítica (9.8) | 21% | — | Themographics Listingo | 12/12/2022 | 17/6/2026 | The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE | |
| Modificada | Media (6.1) | 0.70% | — | Radiustheme Classified Listing | 16/9/2022 | 17/6/2026 | The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.62% | — | Radiustheme Classified ListingRadiustheme Classified Listing Store & MembershipRadiustheme ClassimaRadiustheme Classima Core | 16/9/2022 | 17/6/2026 | The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected… | |
| Modificada | Crítica (9.8) | 33% | — | Skyoftech SO Listing Tabs | 17/5/2022 | 17/6/2026 | The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code execution because of deserialization of untrusted data. | |
| Modificada | Alta (7.2) | 1.5% | — | Wpsocket Automatic Grid Image Listing | 16/5/2022 | 17/6/2026 | The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE | |
| Modificada | Media (4.8) | 0.62% | — | Unboxinteractive Petfinder-listings | 14/3/2022 | 17/6/2026 | The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.8) | 8.5% | 💥 Exploit | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 21/12/2021 | 17/6/2026 | The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections | |
| Modificada | Alta (8.8) | 1.3% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 8/11/2021 | 17/6/2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using… | |
| Modificada | Media (4.8) | 0.91% | — | Wpgenious Wpgenius JOB Listing | 15/10/2021 | 17/6/2026 | The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/admin/class/class-wpgenious-job-listing-options.php file which allowed attackers with administrative user access to inject arbitrary web… | |
| Modificada | Crítica (9.8) | 2.1% | — | Stylemixthemes Ulisting | 27/9/2021 | 17/6/2026 | Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom. | |
| Modificada | Crítica (9.8) | 2.2% | — | Stylemixthemes Ulisting | 27/9/2021 | 17/6/2026 | Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration. | |
| Modificada | Media (6.5) | 0.44% | — | Stylemixthemes Ulisting | 27/9/2021 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles. | |
| Modificada | Alta (8.8) | 0.44% | — | Stylemixthemes Ulisting | 27/9/2021 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages. | |
| Modificada | Media (4.8) | 0.77% | — | Stylemixthemes Ulisting | 27/9/2021 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin – uListing allows Reflected XSS.This issue affects Directory Listings WordPress plugin – uListing: from n/a through 2.0.5. | |
| Modificada | Alta (8.8) | 1.1% | — | Stylemixthemes Ulisting | 27/9/2021 | 17/6/2026 | Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5). | |
| Modificada | Media (4.3) | 0.44% | — | Stylemixthemes Ulisting | 27/9/2021 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings. | |
| Modificada | Media (5.4) | 0.88% | 💥 PoC | House Rental AND Property Listing PHP Project House Rental AND Property Listing PHP | 23/7/2021 | 17/6/2026 | Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number. | |
| Modificada | Media (4.3) | 0.47% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example) | |
| Modificada | Media (5.4) | 0.65% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin. | |
| Modificada | Media (6.5) | 0.71% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files, which could then be downloaded by the attacker to get access to PII, such as email, home addresses… | |
| Modificada | Alta (7.2) | 1.6% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE | |
| Modificada | Alta (8.8) | 0.67% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it could lead to RCE. | |
| Modificada | Alta (8.8) | 0.67% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues. |