Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
721 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.36% | — | Vibethemes BP Social ConnectAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes BP Social Connect bp-social-connect allows Stored XSS.This issue affects BP Social Connect: from n/a through <= 1.6.2. | |
| Aplazada | Alta (7.1) | 0.19% | — | Ninotheme Nino Social ConnectAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ninotheme Nino Social Connect nino-social-connect allows Stored XSS.This issue affects Nino Social Connect: from n/a through <= 2.0. | |
| Aplazada | Alta (7.1) | 0.21% | — | Vfvalent Social-bookmarking-reloadedAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in vfvalent Social Bookmarking RELOADED social-bookmarking-reloaded allows Stored XSS.This issue affects Social Bookmarking RELOADED: from n/a through <= 3.18. | |
| Aplazada | Alta (7.1) | 0.21% | — | Bdoga Social CrowdAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bdoga Social Crowd social-crowd allows Stored XSS.This issue affects Social Crowd: from n/a through <= 0.9.6.1. | |
| Aplazada | Media (4.3) | 0.43% | — | Joao Romao Social Share Buttons AND Analytics Plugin Getsocial IOAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Joao Romao Social Share Buttons & Analytics Plugin – GetSocial.io wp-share-buttons-analytics-by-getsocial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Buttons & Analytics Plugin – GetSocial.io: from n/a through <= 4.5. | |
| Aplazada | Media (6.5) | 0.40% | — | Suresh Prasad Showeblogin Showeblogin SocialAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh Prasad Showeblogin Social showeblogin-facebook-page-like-box allows DOM-Based XSS.This issue affects Showeblogin Social: from n/a through <= 7.0. | |
| Aplazada | Media (5.9) | 0.41% | — | Socialintents Live-chat-support-by-social-intentsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in socialintents Social Intents live-chat-support-by-social-intents allows Stored XSS.This issue affects Social Intents: from n/a through <= 1.6.19. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Reputeinfosystems Social Share AND Social LockerAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems Social Share And Social Locker social-share-and-social-locker-arsocial allows Blind SQL Injection.This issue affects Social Share And Social Locker: from n/a through <= 1.4.2. | |
| Aplazada | Alta (7.1) | 0.24% | — | Reputeinfosystems Social Share AND Social LockerAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems Social Share And Social Locker social-share-and-social-locker-arsocial allows Reflected XSS.This issue affects Social Share And Social Locker: from n/a through <= 1.4.1. | |
| Aplazada | Media (4.3) | 0.25% | — | Repuso Social-testimonials-and-reviews-widgetAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso social-testimonials-and-reviews-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social proof testimonials and reviews by Repuso: from n/a through <= 5.21. | |
| Aplazada | Media (6.5) | 0.36% | — | Snapwidget Social Photo Feed WidgetAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snapwidget SnapWidget Social Photo Feed Widget snapwidget-wp-instagram-widget allows DOM-Based XSS.This issue affects SnapWidget Social Photo Feed Widget: from n/a through <= 1.1.0. | |
| Analizada | Alta (8.1) | 0.40% | — | Getopensocial Open Social | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10. | |
| Analizada | Crítica (9.1) | 0.39% | — | Getopensocial Open Social | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10. | |
| Aplazada | Media (5.4) | 0.15% | — | Nertworks ALL IN ONE Social Share ToolsAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nertworks NertWorks All in One Social Share Tools nertworks-all-in-one-social-share-tools allows Cross Site Request Forgery.This issue affects NertWorks All in One Social Share Tools: from n/a through <= 1.26. | |
| Aplazada | Alta (7.1) | 0.35% | — | Riyaz GetsocialAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Riyaz GetSocial getsocial allows Reflected XSS.This issue affects GetSocial: from n/a through <= 2.0.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Ghoszylab Gallery FOR Social Photo Feed Instagram LiteAI | 25/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo feed-instagram-lite allows Stored XSS.This issue affects Gallery for Social Photo: from n/a through <= 1.0.0.35. | |
| Analizada | Baja (3.5) | 0.26% | — | Cm-wp Social Slider Widget | 25/3/2025 | 17/6/2026 | To exploit the vulnerability, it is necessary: | |
| Modificada | Media (5.4) | 0.28% | — | Catchsquare WP Social Widget | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget wp-social-widget allows Stored XSS.This issue affects WP Social Widget: from n/a through <= 2.2.7. | |
| Analizada | Baja (3.5) | 0.27% | — | Socialsnap Social Snap | 11/3/2025 | 17/6/2026 | The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin through 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html… | |
| Analizada | Crítica (9.8) | 0.47% | — | Miniorange Social Login | 8/3/2025 | 17/6/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.39% | — | Socialevolution WP Find Your NearestAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SocialEvolution WP Find Your Nearest wp-find-your-nearest allows Reflected XSS.This issue affects WP Find Your Nearest: from n/a through <= 0.3.1. | |
| Aplazada | Media (6.5) | 0.15% | — | Kareemsultan Social LinksAI | 3/3/2025 | 18/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in kareemsultan Social Links social-links allows Cross Site Request Forgery. This issue affects Social Links: from n/a through 1.0.11. | |
| Aplazada | Alta (7.6) | 0.75% | — | Kareemsultan Social LinksAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kareemsultan Social Links social-links allows Command Line Execution through SQL Injection.This issue affects Social Links: from n/a through <= 1.2. | |
| Aplazada | Alta (7.1) | 0.37% | — | Mitchell Bundy WP Social LinksAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bundy WP Social Links wp-social-links allows Reflected XSS.This issue affects WP Social Links: from n/a through <= 0.3.1. | |
| Analizada | Media (4.3) | 0.20% | — | Wpmet WP Social Login AND Register Social Counter | 28/2/2025 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. This is due to missing or incorrect nonce validation on the counter_access_key_setup() function. This makes it possible for unauthenticated attackers to update… |