Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Basteln3rk Save Import Image From URLAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in basteln3rk Save & Import Image from URL save-import-image-from-url allows Reflected XSS.This issue affects Save & Import Image from URL: from n/a through <= 0.7. | |
| Aplazada | Alta (7.5) | 0.61% | — | WM Options Import ExportAI | 22/1/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Web Mumbai WM Options Import Export wm-options-import-export allows Retrieve Embedded Sensitive Data.This issue affects WM Options Import Export: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.5) | 0.34% | — | Import ANY XML OR CSV File TO Wordpress PROAI | 19/1/2025 | 17/6/2026 | The Import any XML or CSV File to WordPress PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level… | |
| Aplazada | Alta (7.1) | 0.31% | — | Poco Blogger Image ImportAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poco Blogger Image Import allows Stored XSS.This issue affects Blogger Image Import: from 2.1 through n/a. | |
| Aplazada | Alta (7.1) | 0.17% | — | Sana Ullah Import Users TO MailchimpAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sana Ullah Import Users to MailChimp import-users-to-mailchimp allows Stored XSS.This issue affects Import Users to MailChimp: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.19% | — | Kreg Steppe Auphonic ImporterAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kreg Steppe Auphonic Importer auphonic-importer allows Stored XSS.This issue affects Auphonic Importer: from n/a through <= 1.5.1. | |
| Analizada | Alta (8.8) | 0.20% | — | Migrate Queue Importer Project Migrate Queue Importer | 9/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1. | |
| Aplazada | Media (6.5) | 0.35% | — | Portone Iamport-paymentAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PORTONE 아임포트 결제버튼 생성 플러그인 iamport-payment allows Stored XSS.This issue affects 아임포트 결제버튼 생성 플러그인: from n/a through <= 1.1.19. | |
| Aplazada | Media (5.3) | 0.35% | — | Akshaymenariya Export Import MenusAI | 7/1/2025 | 17/6/2026 | The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dsp_export_import_menus() function in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to export menu data and settings. | |
| Aplazada | Media (6.1) | 0.36% | — | Xylusthemes WP Smart ImportAI | 4/1/2025 | 17/6/2026 | The WP Smart Import : Import any XML File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ page’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (7.6) | 0.43% | — | Soflyy WP ALL Import PROAI | 17/12/2024 | 17/6/2026 | The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to… | |
| Aplazada | Media (5.4) | 0.41% | — | Awfowler Easy Site ImporterAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awfowler Easy Site Importer easy-site-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Site Importer: from n/a through <= 1.0.1. | |
| Aplazada | Crítica (9.3) | 0.54% | — | Binarycarpenter Launchpage.app ImporterAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BinaryCarpenter LaunchPage.app Importer launchpage-app-importer allows SQL Injection.This issue affects LaunchPage.app Importer: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.21% | — | Shambhu Patnaik WP Flipkart ImporterAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shambhu Patnaik WP Flipkart Importer wp-flipkart-importer allows Stored XSS.This issue affects WP Flipkart Importer: from n/a through <= 1.4. | |
| Aplazada | Media (6.1) | 0.37% | — | Import Eventbrite EventsAI | 14/12/2024 | 17/6/2026 | The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.2) | 1.8% | 💥 PoC | Crafthemes Demo ImportAI | 14/12/2024 | 17/6/2026 | The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'process_uploaded_files' function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload… | |
| Aplazada | Crítica (9.9) | 1.5% | 💥 PoC | Sidngr Import Export FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2. | |
| Aplazada | Media (5.3) | 0.55% | — | ImportifyAI | 9/12/2024 | 17/6/2026 | Insertion of Sensitive Information Into Debugging Code vulnerability in importify Importify (Dropshipping WooCommerce) importify allows Retrieve Embedded Sensitive Data.This issue affects Importify (Dropshipping WooCommerce): from n/a through <= 1.0.4. | |
| Aplazada | Media (4.3) | 0.40% | — | Onthegosystems Qtranslate X CleanupAIOnthegosystems Wpml ImportAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in OntheGoSystems qTranslate X Cleanup and WPML Import allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects qTranslate X Cleanup and WPML Import: from n/a through 3.0.1. | |
| Analizada | Media (6.1) | 0.38% | — | Thimpress Learnpress Export Import | 15/11/2024 | 17/6/2026 | The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learnpress_import_form_server' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (10) | 0.51% | — | Webtechglobal Easy CSV ImporterAI | 14/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WebTechGlobal Easy CSV Importer BETA easy-csv-importer allows Upload a Web Shell to a Web Server.This issue affects Easy CSV Importer BETA: from n/a through <= 7.0.0. | |
| Aplazada | Media (5.4) | 0.39% | — | Mekshq Meks Video ImporterAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Meks Meks Video Importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meks Video Importer: from n/a through 1.0.12. | |
| Aplazada | Alta (8.8) | 0.42% | — | Stackthemes Bstone Demo ImporterAI | 29/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege Escalation.This issue affects Bstone Demo Importer: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.9) | 0.31% | — | Codection Import AND Export Users AND CustomersAI | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta allows Stored XSS.This issue affects Import and export users and customers: from n/a through <= 1.27.5. | |
| Analizada | Media (5.4) | 0.30% | — | Sukiwp Suki Sites Import | 18/10/2024 | 17/6/2026 | The Suki Sites Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… |