Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
226 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.62% | — | Dfactory Post Views Counter | 20/9/2021 | 17/6/2026 | The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.4) | 0.62% | — | Geminilabs Site Reviews | 6/9/2021 | 17/6/2026 | The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed | |
| Modificada | Alta (8.8) | 1.6% | — | Handsome Testimonials & Reviews Project Handsome Testimonials & Reviews | 2/8/2021 | 17/6/2026 | The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue. | |
| Modificada | Media (4.8) | 0.62% | — | Gowebsolutions WP Customer Reviews | 24/5/2021 | 17/6/2026 | The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled | |
| Modificada | Media (6.1) | 1.1% | — | Gowebsolutions WP Customer Reviews | 18/3/2021 | 17/6/2026 | Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Chosen-views-tabbar | 16/9/2020 | 17/6/2026 | Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to configure views. | |
| Modificada | Crítica (9.8) | 1.8% | — | Drupal Views Dynamic Field | 16/12/2019 | 17/6/2026 | The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code execution might also be possible. | |
| Modificada | Media (6.1) | 1.3% | — | Drupal Views Builk Operations | 25/11/2019 | 16/6/2026 | Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS)… | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Reviews | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Crítica (9.8) | 1.4% | — | Reviews Module Project Reviews Module | 26/8/2019 | 17/6/2026 | The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js. | |
| Modificada | Alta (8.8) | 0.68% | — | Gowebsolutions WP Customer Reviews | 21/8/2019 | 17/6/2026 | The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools. | |
| Modificada | Media (6.1) | 0.91% | — | Gowebsolutions WP Customer Reviews | 21/8/2019 | 17/6/2026 | The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools. | |
| Modificada | Media (5.4) | 0.65% | — | Consumer Reviews Script Project Consumer Reviews Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box. | |
| Modificada | Media (6.5) | 1.6% | — | Consumer Reviews Script Project Consumer Reviews Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. | |
| Modificada | Media (6.1) | 1.3% | — | Geminilabs Site Reviews | 26/6/2018 | 17/6/2026 | Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Hotel Restaurant Reviews AND Feedback Script Project Hotel Restaurant Reviews AND Feedback Script | 13/12/2017 | 17/6/2026 | Food Order Script 1.0 has SQL Injection via the /list city parameter. | |
| Modificada | Crítica (9.8) | 2.7% | — | Perforce JviewsOracle Data Integrator | 6/4/2017 | 17/6/2026 | Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFacesController servlet in jviews-framework-all.jar does not require explicit… | |
| Modificada | Media (4.3) | 1.1% | — | Bokublock BbadminviewscontrolBokublock Bbadminviewscontrol213 | 30/12/2015 | 17/6/2026 | SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 2.1% | — | Administration Views Project Administration Views | 17/9/2015 | 17/6/2026 | The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler. | |
| Modificada | Media (4.9) | 1.6% | — | Views Bulk Operations Project Views Bulk Operations | 18/8/2015 | 17/6/2026 | The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled. | |
| Modificada | Media (6) | 1.2% | — | Administration Views Project Administration Views | 18/8/2015 | 17/6/2026 | The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to administration pages, which allows remote administrators to bypass intended restrictions via unspecified vectors. | |
| Modificada | Media (5) | 2.6% | — | Views Project Views | 18/8/2015 | 17/6/2026 | The _views_fetch_data method in includes/cache.inc in the Views module 7.x-3.5 through 7.x-3.10 for Drupal does not rebuild the full cache if the static cache is not empty, which allows remote attackers to bypass intended filters and obtain access to hidden content via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | Views Project Views | 21/4/2015 | 17/6/2026 | The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (4.9) | 1.6% | — | Views Project Views | 21/4/2015 | 17/6/2026 | Open redirect vulnerability in the Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal, when the Views UI submodule is enabled, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to the break lock page for… |