Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.54%—Enable SVG Uploads Project Enable SVG Uploads10/7/202317/6/2026
The Enable SVG Uploads WordPress plugin through 2.1.5 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
ModificadaMedia (6.1)0.38%—Manage Upload Limit Project Manage Upload Limit21/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WpSimpleTools Manage Upload Limit plugin <= 1.0.4 versions.
ModificadaMedia (5.3)0.51%—Upload Resume Project Upload Resume19/6/202317/6/2026
The Upload Resume WordPress plugin through 1.2.0 does not validate the captcha parameter when uploading a resume via the resume_upload_form shortcode, allowing unauthenticated visitors to upload arbitrary media files to the site.
ModificadaMedia (4.8)0.44%—Wpfactory File Renaming ON Upload19/6/202317/6/2026
The File Renaming on Upload WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.1)0.22%—Auto Upload Images Project Auto Upload Images13/6/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ali Irani Auto Upload Images plugin <= 3.3 versions allows Stored Cross-Site Scripting (XSS).
ModificadaMedia (5.5)0.38%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO9/6/202317/6/2026
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaMedia (4.9)1.7%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO9/6/202317/6/2026
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default)…
ModificadaAlta (8.8)0.25%—Resize AT Upload Plus Project Resize AT Upload Plus26/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Daniel Mores, A. Huizinga Resize at Upload Plus plugin <= 1.3 versions.
ModificadaMedia (4.8)0.37%—Upload File Type Settings Plugin Project Upload File Type Settings Plugin26/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sebastian Krysmanski Upload File Type Settings plugin <= 1.1 versions.
ModificadaAlta (8.8)0.25%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 724/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.
ModificadaMedia (6.1)0.54%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 717/4/202317/6/2026
The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a…
ModificadaMedia (4.8)0.47%—Auto Rename Media ON Upload Project Auto Rename Media ON Upload10/4/202317/6/2026
The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaCrítica (9.8)3.0%💥 PoCCodedropz Drag AND Drop Multiple File Upload - Contact Form 71/3/202317/6/2026
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack…
ModificadaAlta (7.5)49%💥 PoCApache Commons FileuploadDebian Linux20/2/20237/10/2026
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
ModificadaCrítica (9.1)29%—Images Optimize AND Upload CF7 Project Images Optimize AND Upload CF716/1/202317/6/2026
The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack.
ModificadaCrítica (9.8)0.86%—Ecodev Media Upload10/1/202317/6/2026
A vulnerability has been found in fabarea media_upload on TYPO3 and classified as critical. This vulnerability affects the function getUploadedFileList of the file Classes/Service/UploadFileService.php. The manipulation leads to pathname traversal. Upgrading to version 0.9.0 is able to address this issue. The patch is…
ModificadaAlta (8.8)0.36%—Auto Upload Images Project Auto Upload Images21/12/202217/6/2026
A vulnerability was found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file src/setting-page.php of the component Settings Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. Upgrading to…
ModificadaMedia (6.1)0.54%—Auto Upload Images Project Auto Upload Images21/12/202217/6/2026
A vulnerability has been found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 3.3.1 is able to address this issue. The name of the…
ModificadaMedia (4.3)0.59%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 717/10/202217/6/2026
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.
ModificadaMedia (6.1)0.56%—Picuploader Project Picuploader7/10/202217/6/2026
PicUploader v2.6.3 was discovered to contain cross-site scripting (XSS) vulnerability via the setStorageParams function in SettingController.php.
ModificadaCrítica (9.8)1.4%—Creativedream File Uploader Project Creativedream File Uploader3/10/202217/6/2026
Arbitrary file upload vulnerability in php uploader
ModificadaCrítica (9.8)1.2%—Ec-cube Product Image Bulk Upload27/9/202217/6/2026
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE…
ModificadaMedia (6.1)0.45%—Picuploader Project Picuploader30/8/202217/6/2026
PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index.php.
ModificadaAlta (7.2)1.2%—Uploading Svg, Webp AND ICO Files Project Uploading Svg, Webp AND ICO Files23/8/202217/6/2026
Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.
ModificadaMedia (5.4)0.56%—Uploading Svg, Webp AND ICO Files Project Uploading Svg, Webp AND ICO Files23/8/202217/6/2026
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.
Orbitaley — Vulnerabilidades