Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

282 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.26%—Wpgogo Custom Post Type Page Template18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Post Type Page Template.This issue affects Custom Post Type Page Template: from n/a through 1.1.
ModificadaMedia (6.1)0.41%—Gillesdumas Which Template File15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gilles Dumas which template file allows Reflected XSS.This issue affects which template file: from n/a through 4.9.0.
ModificadaMedia (5.4)0.40%—Brainstormforce Starter Templates7/12/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.
ModificadaAlta (7.5)0.97%💥 PoCThemeisle Cloud Templates & Patterns Collection23/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collection.This issue affects Cloud Templates & Patterns collection: from n/a through 1.2.2.
ModificadaMedia (6.1)0.41%—Ioannup Edit Woocommerce Templates16/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ioannup Edit WooCommerce Templates plugin <= 1.1.1 versions.
ModificadaAlta (8.8)0.28%—Wpexperts Email Templates Customizer AND Designer7/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpexpertsio Email Templates Customizer and Designer for WordPress and WooCommerce email-templates allows Cross Site Request Forgery.This issue affects Email Templates Customizer and Designer for WordPress and WooCommerce: from n/a through 1.4.2.
ModificadaAlta (7.5)0.61%—Templately6/11/202317/6/2026
The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.
ModificadaMedia (6.1)0.29%—Ericteubert Archivist - Custom Archive Templates27/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions.
ModificadaAlta (8.8)0.21%—Gillesdumas Which Template File16/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Gilles Dumas which template file plugin <= 4.6.0 versions.
ModificadaAlta (8.8)0.26%—Dotsquares WP Custom Post Template10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dotsquares WP Custom Post Template <= 1.0 versions.
ModificadaMedia (6.1)0.38%—Praveengoswami Advanced Category Template17/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Praveen Goswami Advanced Category Template plugin <= 0.1 versions.
ModificadaMedia (6.1)0.41%—Wpgogo Custom Field Template7/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.9 versions.
ModificadaAlta (7.5)46%💥 ExploitTemplatecookie Adlisting5/8/202317/6/2026
A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this…
ModificadaAlta (8.8)0.59%—Axis License Plate Verifier3/8/202317/6/2026
User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections.
ModificadaAlta (8.8)0.83%—Axis License Plate Verifier3/8/202317/6/2026
User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution.
ModificadaAlta (8.8)0.83%—Axis License Plate Verifier3/8/202317/6/2026
User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution.
ModificadaCrítica (9.8)0.63%—Axis License Plate Verifier3/8/202317/6/2026
Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application.
ModificadaCrítica (9.8)0.63%—Axis License Plate Verifier3/8/202317/6/2026
Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems.
ModificadaAlta (8.8)0.67%—Axis License Plate Verifier3/8/202317/6/2026
A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges.
ModificadaMedia (4.3)0.38%—Coolplugins Process Steps Template Designer12/7/202317/6/2026
The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request…
ModificadaAlta (8.8)0.26%—Template Debugger Project Template Debugger11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Danny Hearnah - ChubbyNinjaa Template Debugger plugin <= 3.1.2 versions.
ModificadaAlta (8.8)0.32%—Wpgogo Custom Field Template10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.8 versions.
ModificadaMedia (4.3)0.38%—Wpgogo Custom Field Template1/7/202317/6/2026
The Custom Field Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on the edit_meta_value() function. This makes it possible for unauthenticated attackers to edit meta field values via a forged request…
ModificadaMedia (5.4)0.75%—Jenkins Template Workflows14/6/202317/6/2026
Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create jobs.
ModificadaMedia (6.1)0.45%—Udecode Plate9/6/202317/6/2026
@udecode/plate-link is the link handler for the udecode/plate rich-text editor plugin system for Slate & React. Affected versions of the link plugin and link UI component do not sanitize URLs to prevent use of the `javascript:` scheme. As a result, links with JavaScript URLs can be inserted into the Plate editor…