Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

226 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.62%—Dfactory Post Views Counter20/9/202117/6/2026
The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed
ModificadaMedia (5.4)0.62%—Geminilabs Site Reviews6/9/202117/6/2026
The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed
ModificadaAlta (8.8)1.6%—Handsome Testimonials & Reviews Project Handsome Testimonials & Reviews2/8/202117/6/2026
The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue.
ModificadaMedia (4.8)0.62%—Gowebsolutions WP Customer Reviews24/5/202117/6/2026
The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled
ModificadaMedia (6.1)1.1%—Gowebsolutions WP Customer Reviews18/3/202117/6/2026
Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML.
ModificadaMedia (5.4)0.73%—Jenkins Chosen-views-tabbar16/9/202017/6/2026
Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to configure views.
ModificadaCrítica (9.8)1.8%—Drupal Views Dynamic Field16/12/201917/6/2026
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code execution might also be possible.
ModificadaMedia (6.1)1.3%—Drupal Views Builk Operations25/11/201916/6/2026
Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS)…
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaMedia (6.1)0.92%—Awesomemotive Easy Digital DownloadsEasydigitaldownloads Reviews23/10/201917/6/2026
The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
ModificadaCrítica (9.8)1.4%—Reviews Module Project Reviews Module26/8/201917/6/2026
The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.
ModificadaAlta (8.8)0.68%—Gowebsolutions WP Customer Reviews21/8/201917/6/2026
The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
ModificadaMedia (6.1)0.91%—Gowebsolutions WP Customer Reviews21/8/201917/6/2026
The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
ModificadaMedia (5.4)0.65%—Consumer Reviews Script Project Consumer Reviews Script21/3/201917/6/2026
PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box.
ModificadaMedia (6.5)1.6%—Consumer Reviews Script Project Consumer Reviews Script21/3/201917/6/2026
PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
ModificadaMedia (6.1)1.3%—Geminilabs Site Reviews26/6/201817/6/2026
Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaCrítica (9.8)3.0%💥 ExploitHotel Restaurant Reviews AND Feedback Script Project Hotel Restaurant Reviews AND Feedback Script13/12/201717/6/2026
Food Order Script 1.0 has SQL Injection via the /list city parameter.
ModificadaCrítica (9.8)2.7%—Perforce JviewsOracle Data Integrator6/4/201717/6/2026
Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFacesController servlet in jviews-framework-all.jar does not require explicit…
ModificadaMedia (4.3)1.1%—Bokublock BbadminviewscontrolBokublock Bbadminviewscontrol21330/12/201517/6/2026
SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5)2.1%—Administration Views Project Administration Views17/9/201517/6/2026
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.
ModificadaMedia (4.9)1.6%—Views Bulk Operations Project Views Bulk Operations18/8/201517/6/2026
The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.
ModificadaMedia (6)1.2%—Administration Views Project Administration Views18/8/201517/6/2026
The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to administration pages, which allows remote administrators to bypass intended restrictions via unspecified vectors.
ModificadaMedia (5)2.6%—Views Project Views18/8/201517/6/2026
The _views_fetch_data method in includes/cache.inc in the Views module 7.x-3.5 through 7.x-3.10 for Drupal does not rebuild the full cache if the static cache is not empty, which allows remote attackers to bypass intended filters and obtain access to hidden content via unspecified vectors.
ModificadaMedia (4)1.1%—Views Project Views21/4/201517/6/2026
The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
ModificadaMedia (4.9)1.6%—Views Project Views21/4/201517/6/2026
Open redirect vulnerability in the Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal, when the Views UI submodule is enabled, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to the break lock page for…
Orbitaley — Vulnerabilidades