Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.22% | — | E-plugins JobbankAI | 6/1/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank jobbank allows Reflected XSS.This issue affects JobBank: from n/a through <= 1.2.2. | |
| Aplazada | Media (5.3) | 0.21% | — | Gsplugins GS Portfolio FOR EnvatoAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in GS Plugins GS Portfolio for Envato gs-envato-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Portfolio for Envato: from n/a through <= 1.4.2. | |
| Aplazada | Media (4.3) | 0.22% | — | Themeboy Hide PluginsAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in ThemeBoy Hide Plugins hide-plugins allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hide Plugins: from n/a through <= 1.0.4. | |
| Aplazada | Media (4.3) | 0.18% | — | Kraftplugins Demo Importer PlusAI | 30/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Importer Plus: from n/a through <= 2.0.8. | |
| Aplazada | Media (6.5) | 0.16% | — | Pickplugins Post GridAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23. | |
| Aplazada | Media (4.3) | 0.13% | — | Pluginsware Advanced Classifieds AND Directory PROAI | 24/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in pluginsware Advanced Classifieds & Directory Pro advanced-classifieds-and-directory-pro allows Cross Site Request Forgery.This issue affects Advanced Classifieds & Directory Pro: from n/a through <= 3.2.9. | |
| Aplazada | Media (4.3) | 0.19% | — | Spiffyplugins Spiffy CalendarAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spiffy Calendar: from n/a through <= 5.0.7. | |
| Aplazada | Media (6.1) | 0.21% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 21/12/2025 | 17/6/2026 | The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.2) | 0.24% | — | Bplugins Html5 Audio PlayerAI | 19/12/2025 | 17/6/2026 | The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions from 2.4.0 up to, and including, 2.5.1 via the getIcyMetadata() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Aplazada | Media (6.5) | 0.24% | — | Pickplugins Post GridAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17. | |
| Aplazada | Media (5.3) | 0.24% | — | Pickplugins Post Grid AND Gutenberg BlocksAI | 18/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23. | |
| Aplazada | Alta (8.8) | 0.35% | — | Kraftplugins Demo Importer PlusAI | 18/12/2025 | 17/6/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missing capability check on the Ajax::handle_request() function in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.29% | — | Fantasticplugins Woocommerce Recover Abandoned CartAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in FantasticPlugins WooCommerce Recover Abandoned Cart rac allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Recover Abandoned Cart: from n/a through <= 24.6.0. | |
| Aplazada | Alta (7.5) | 0.35% | — | Bplugins PDF FOR Gravity FormsAIGravityforms Gravity FormsAI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Gravity Forms + Drag And Drop Template Builder pdf-for-gravity-forms allows Object Injection.This issue affects PDF for Gravity Forms + Drag And Drop Template Builder: from n/a through <= 6.5.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Bplugins Parallax SectionAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in bPlugins Parallax Section block parallax-section allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Parallax Section block: from n/a through <= 1.0.9. | |
| Aplazada | Alta (8.8) | 0.36% | — | E-plugins Hotel ListingAI | 18/12/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation.This issue affects Hotel Listing: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.2) | 0.39% | — | Silverplugins217 Custom-fields-account-registration-for-woocommerceAI | 18/12/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in silverplugins217 Custom Fields Account Registration For Woocommerce custom-fields-account-registration-for-woocommerce allows Privilege Escalation.This issue affects Custom Fields Account Registration For Woocommerce: from n/a through <= 1.2. | |
| Aplazada | Media (4.3) | 0.12% | — | Download Plugins AND Themes IN ZIP From DashboardAI | 17/12/2025 | 28/9/2026 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.6. This is due to missing or incorrect nonce validation on the download_plugin_bulk and download_theme_bulk functions. This makes it possible for… | |
| Aplazada | Media (5.9) | 0.21% | — | Barn2 Plugins Document Library LiteAI | 16/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows DOM-Based XSS.This issue affects Document Library Lite: from n/a through <= 1.1.7. | |
| Aplazada | Media (5.3) | 0.30% | — | Barn2 Plugins Document Library LiteAI | 16/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Document Library Lite: from n/a through <= 1.1.7. | |
| Aplazada | Media (4.3) | 0.22% | — | E-plugins Directory PROAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6. | |
| Analizada | Baja (3.6) | 0.14% | — | Linuxfoundation CNI Network Plugins | 10/12/2025 | 17/6/2026 | The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versions 1.6.0 through 1.8.0 inadvertently forward all traffic with the same destination port as the host port when the portmap plugin is configured with the nftables backend, thus ignoring the… | |
| Aplazada | Media (4.3) | 0.13% | — | Fullworksplugins Quick Contact FormAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Cross Site Request Forgery.This issue affects Quick Contact Form: from n/a through <= 8.2.5. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Pickplugins User VerificationAI | 5/12/2025 | 17/6/2026 | The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.44. This is due to the plugin not properly validating that an OTP was generated before comparing it… | |
| Aplazada | Alta (8.8) | 0.55% | — | Kraftplugins Demo Importer PlusAI | 5/12/2025 | 25/9/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible… |