Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.38% | — | Wedevs WP User FrontendAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8. | |
| Aplazada | Media (6.5) | 0.33% | — | Wpexperts NEW User ApproveAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through <= 3.2.3. | |
| Aplazada | Media (6.5) | 0.31% | — | Wedevs WP User FrontendAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5. | |
| Aplazada | Media (5.4) | 0.30% | — | User Registration MembershipAI | 24/3/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_permissions()` method only checking for `edit_posts` capability instead… | |
| Analizada | Crítica (9.3) | 0.40% | — | Csprousers Csweb | 23/3/2026 | 17/6/2026 | Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha. | |
| Analizada | Media (5.1) | 0.21% | — | Csprousers Csweb | 23/3/2026 | 17/6/2026 | Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that executes in a victim's browser. Fixed in 8.1.0 alpha. | |
| Analizada | Alta (8.7) | 0.53% | — | Csprousers Csweb | 23/3/2026 | 17/6/2026 | Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha. | |
| Analizada | Alta (8.7) | 0.49% | — | Csprousers Csweb | 23/3/2026 | 17/6/2026 | Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha. | |
| Aplazada | Alta (8.1) | 0.54% | 💥 PoC | Codection Import AND Export Users AND CustomersAI | 21/3/2026 | 17/6/2026 | The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields'… | |
| Aplazada | Alta (8.8) | 0.44% | — | Expire UsersAI | 21/3/2026 | 17/6/2026 | The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_role' meta through the 'save_extra_user_profile_fields' function. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.19% | — | User FrontendAI | 16/3/2026 | 17/6/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for… | |
| Pendiente de análisis | Alta (8.8) | 0.13% | — | Microsoft Directx End-user Runtime WEB InstallerAI | 11/3/2026 | 17/6/2026 | In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file during the installation process, which may result in unintended elevation of privileges. During installation, the installer runs with HIGH integrity and downloads executables and DLLs to the %TEMP%… | |
| Aplazada | Crítica (9.8) | 28% | 💥 Exploit | User Registration MembershipAI | 3/3/2026 | 17/6/2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role… | |
| Aplazada | Alta (8.8) | 0.55% | — | Wedevs User FrontendAI | 26/2/2026 | 17/6/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext'… | |
| Aplazada | Media (5.3) | 0.19% | — | User Registration AND MembershipAI | 26/2/2026 | 17/6/2026 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'member_id' user controlled key. This makes… | |
| Aplazada | Alta (8.1) | 0.36% | — | User Registration MembershipAI | 26/2/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newly registered user on the site who has… | |
| Aplazada | Alta (7.7) | 0.47% | — | Vanquish User Extra FieldsAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue affects User Extra Fields: from n/a through <= 17.0. | |
| Aplazada | Alta (8.6) | 0.54% | — | Vanquish User Extra FieldsAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue affects User Extra Fields: from n/a through <= 17.0. | |
| Aplazada | Alta (8.6) | 0.27% | — | Wpexperts NEW User ApproveAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through <= 3.2.0. | |
| Aplazada | Media (6.5) | 0.33% | — | 100plugins Open User MAPAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 100plugins Open User Map open-user-map allows Path Traversal.This issue affects Open User Map: from n/a through <= 1.4.16. | |
| Aplazada | Alta (7.1) | 0.18% | — | Vanquish User Extra FieldsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Reflected XSS.This issue affects User Extra Fields: from n/a through <= 16.8. | |
| Aplazada | Media (5.3) | 0.37% | — | Plugin-planet User Submitted PostsAI | 18/2/2026 | 17/6/2026 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 20260113. This is due to the `usp_get_submitted_category()` function accepting user-submitted category IDs from the POST body without validating… | |
| Aplazada | Media (4.3) | 0.17% | — | Frontend User NotesAI | 18/2/2026 | 17/6/2026 | The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'funp_ajax_modify_notes' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (5.5) | 0.36% | 💥 PoC | User Language SwitchAI | 14/2/2026 | 17/6/2026 | The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web… | |
| Aplazada | Media (4.4) | 0.25% | — | User Language SwitchAI | 14/2/2026 | 17/6/2026 | The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_language_switch' parameter in all versions up to, and including, 1.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… |