Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.43% | — | Advancedcustomfields Advanced Custom Fields | 20/6/2024 | 17/6/2026 | The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access | |
| Modificada | Alta (8.8) | 0.63% | — | Custom Field Suite Project Custom Field Suite | 20/6/2024 | 17/6/2026 | The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient sanitization of input prior to being used in a call to the eval() function. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.51% | — | Custom Field Suite Project Custom Field Suite | 20/6/2024 | 17/6/2026 | The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, 2.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.41% | — | Custom Field Suite Project Custom Field Suite | 20/6/2024 | 17/6/2026 | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Modificada | Media (5.4) | 0.33% | — | Custom Field Suite Project Custom Field Suite | 12/6/2024 | 17/6/2026 | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (4.3) | 0.44% | — | Navz ACF Photo Gallery FieldAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Navneil Naicker ACF Photo Gallery Field.This issue affects ACF Photo Gallery Field: from n/a through 2.6. | |
| Modificada | Media (4.8) | 0.25% | — | Wpgogo Custom Field Template | 11/6/2024 | 17/6/2026 | The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Modificada | Media (5.4) | 0.26% | — | Wpgogo Custom Field Template | 11/6/2024 | 17/6/2026 | The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom field name column in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied custom fields. This makes it possible for authenticated attackers… | |
| Modificada | Media (4.3) | 0.29% | — | Wpgogo Custom Field Template | 11/6/2024 | 17/6/2026 | The Custom Field Template plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the 'cft' shortcode. This makes it possible for authenticated attackers with contributor access and above, to extract sensitive data including arbitrary post metadata. | |
| Modificada | Media (5.4) | 0.26% | — | Wpgogo Custom Field Template | 11/6/2024 | 17/6/2026 | The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cpt' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied post meta. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5.3) | 0.33% | — | Themeisle Product Addons & Fields FOR Woocommerce | 10/6/2024 | 17/6/2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce allows Code Inclusion.This issue affects PPOM for WooCommerce: from n/a through 32.0.20. | |
| Modificada | Crítica (9.1) | 0.59% | — | Themehigh Checkout Field Editor FOR Woocommerce | 10/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field Editor for WooCommerce (Pro) allows Functionality Misuse, File Manipulation.This issue affects Checkout Field Editor for WooCommerce (Pro): from n/a through 3.6.2. | |
| Aplazada | Crítica (9.9) | 0.59% | — | Wpengine INC Advanced Custom Fields PROAI | 10/6/2024 | 17/6/2026 | Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows PHP Local File Inclusion.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10. | |
| Aplazada | Alta (8.5) | 0.43% | — | Wpengine INC Advanced Custom Fields PROAI | 10/6/2024 | 17/6/2026 | Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows Code Injection.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10. | |
| Modificada | Crítica (9.8) | 0.36% | — | Softlabbd Upload Fields FOR Wpforms | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: from n/a through 1.0.2. | |
| Modificada | Alta (8.8) | 0.35% | — | Websupporter Filter Custom Fields & Taxonomies Light Project Websupporter Filter Custom Fields & Taxonomies Light | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Websupporter Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05. | |
| Modificada | Alta (8.8) | 0.32% | — | Wpdesk Flexible Checkout Fields | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Desk Flexible Checkout Fields for WooCommerce.This issue affects Flexible Checkout Fields for WooCommerce: from n/a through 4.1.2. | |
| Analizada | Media (4.3) | 0.31% | — | Codepeople Calculated Fields Form | 3/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople Calculated Fields Form allows Functionality Misuse.This issue affects Calculated Fields Form: from n/a through 1.1.120. | |
| Aplazada | Media (5.3) | 0.54% | — | Fmeaddons Conditional Checkout Fields FOR WoocommerceAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditional Checkout Fields for WooCommerce: from n/a through 1.2.3. | |
| Modificada | Media (4.8) | 0.56% | — | Custom Field Suite Project Custom Field Suite | 14/5/2024 | 17/6/2026 | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access,… | |
| Aplazada | Media (4.3) | 0.44% | — | Themelocation Custom Woocommerce Checkout Fields EditorAI | 14/5/2024 | 17/6/2026 | Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0. | |
| Aplazada | Media (5.5) | 0.42% | — | Where DID YOU Hear About US Checkout Field FOR WoocommerceAI | 2/5/2024 | 17/6/2026 | The Where Did You Hear About Us Checkout Field for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via order meta in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop… | |
| Aplazada | Media (6.1) | 0.18% | — | Delete Custom FieldsAI | 2/5/2024 | 17/6/2026 | The Delete Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3.1. This is due to missing or incorrect nonce validation on the ajax_delete_field() function. This makes it possible for unauthenticated attackers to delete arbitrary post meta data via a… | |
| Aplazada | Alta (7.5) | 0.99% | — | Fmemodules CustomfieldsAI | 30/4/2024 | 17/6/2026 | Directory Traversal vulnerability in FME Modules customfields v.2.2.7 and before allows a remote attacker to obtain sensitive information via the Custom Checkout Fields, Add Custom Fields to Checkout parameter of the ajax.php | |
| Aplazada | Media (5.4) | 0.31% | — | Yoast Custom Field FinderAI | 29/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Team Yoast Custom field finder.This issue affects Custom field finder: from n/a through 0.3. |