Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.54% | — | Enable SVG Uploads Project Enable SVG Uploads | 10/7/2023 | 17/6/2026 | The Enable SVG Uploads WordPress plugin through 2.1.5 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Modificada | Media (6.1) | 0.38% | — | Manage Upload Limit Project Manage Upload Limit | 21/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WpSimpleTools Manage Upload Limit plugin <= 1.0.4 versions. | |
| Modificada | Media (5.3) | 0.51% | — | Upload Resume Project Upload Resume | 19/6/2023 | 17/6/2026 | The Upload Resume WordPress plugin through 1.2.0 does not validate the captcha parameter when uploading a resume via the resume_upload_form shortcode, allowing unauthenticated visitors to upload arbitrary media files to the site. | |
| Modificada | Media (4.8) | 0.44% | — | Wpfactory File Renaming ON Upload | 19/6/2023 | 17/6/2026 | The File Renaming on Upload WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.22% | — | Auto Upload Images Project Auto Upload Images | 13/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ali Irani Auto Upload Images plugin <= 3.3 versions allows Stored Cross-Site Scripting (XSS). | |
| Modificada | Media (5.5) | 0.38% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 9/6/2023 | 17/6/2026 | The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.9) | 1.7% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 9/6/2023 | 17/6/2026 | The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default)… | |
| Modificada | Alta (8.8) | 0.25% | — | Resize AT Upload Plus Project Resize AT Upload Plus | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Daniel Mores, A. Huizinga Resize at Upload Plus plugin <= 1.3 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Upload File Type Settings Plugin Project Upload File Type Settings Plugin | 26/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sebastian Krysmanski Upload File Type Settings plugin <= 1.1 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions. | |
| Modificada | Media (6.1) | 0.54% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 17/4/2023 | 17/6/2026 | The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a… | |
| Modificada | Media (4.8) | 0.47% | — | Auto Rename Media ON Upload Project Auto Rename Media ON Upload | 10/4/2023 | 17/6/2026 | The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Crítica (9.8) | 3.0% | 💥 PoC | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 1/3/2023 | 17/6/2026 | A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack… | |
| Modificada | Alta (7.5) | 49% | 💥 PoC | Apache Commons FileuploadDebian Linux | 20/2/2023 | 7/10/2026 | Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. | |
| Modificada | Crítica (9.1) | 29% | — | Images Optimize AND Upload CF7 Project Images Optimize AND Upload CF7 | 16/1/2023 | 17/6/2026 | The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack. | |
| Modificada | Crítica (9.8) | 0.86% | — | Ecodev Media Upload | 10/1/2023 | 17/6/2026 | A vulnerability has been found in fabarea media_upload on TYPO3 and classified as critical. This vulnerability affects the function getUploadedFileList of the file Classes/Service/UploadFileService.php. The manipulation leads to pathname traversal. Upgrading to version 0.9.0 is able to address this issue. The patch is… | |
| Modificada | Alta (8.8) | 0.36% | — | Auto Upload Images Project Auto Upload Images | 21/12/2022 | 17/6/2026 | A vulnerability was found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file src/setting-page.php of the component Settings Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. Upgrading to… | |
| Modificada | Media (6.1) | 0.54% | — | Auto Upload Images Project Auto Upload Images | 21/12/2022 | 17/6/2026 | A vulnerability has been found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 3.3.1 is able to address this issue. The name of the… | |
| Modificada | Media (4.3) | 0.59% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 17/10/2022 | 17/6/2026 | The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form. | |
| Modificada | Media (6.1) | 0.56% | — | Picuploader Project Picuploader | 7/10/2022 | 17/6/2026 | PicUploader v2.6.3 was discovered to contain cross-site scripting (XSS) vulnerability via the setStorageParams function in SettingController.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Creativedream File Uploader Project Creativedream File Uploader | 3/10/2022 | 17/6/2026 | Arbitrary file upload vulnerability in php uploader | |
| Modificada | Crítica (9.8) | 1.2% | — | Ec-cube Product Image Bulk Upload | 27/9/2022 | 17/6/2026 | EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE… | |
| Modificada | Media (6.1) | 0.45% | — | Picuploader Project Picuploader | 30/8/2022 | 17/6/2026 | PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index.php. | |
| Modificada | Alta (7.2) | 1.2% | — | Uploading Svg, Webp AND ICO Files Project Uploading Svg, Webp AND ICO Files | 23/8/2022 | 17/6/2026 | Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress. | |
| Modificada | Media (5.4) | 0.56% | — | Uploading Svg, Webp AND ICO Files Project Uploading Svg, Webp AND ICO Files | 23/8/2022 | 17/6/2026 | Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress. |