Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
634 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.36% | — | IPS Grid System Wordpress Book PluginAI | 12/12/2024 | 17/6/2026 | The WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_book_showcase' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user… | |
| Aplazada | Alta (7.3) | 0.60% | — | G5theme Grid PlusAI | 12/12/2024 | 17/6/2026 | The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Aplazada | Media (5.3) | 0.50% | — | Voidthemes Void Elementor Post Grid AddonAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in voidthemes Void Elementor Post Grid Addon for Elementor Page builder void-elementor-post-grid-addon-for-elementor-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Void Elementor Post Grid Addon for Elementor Page builder:… | |
| Analizada | Alta (7.2) | 1.0% | — | Boldgrid Total Upkeep | 26/11/2024 | 17/6/2026 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated… | |
| Aplazada | Alta (7.2) | 1.1% | — | Grid View GalleryAI | 21/11/2024 | 17/6/2026 | The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input from cs_all_photos_details parameter. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No… | |
| Analizada | Alta (8.1) | 0.48% | — | Metagauss Profilegrid | 20/11/2024 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_file_attachment() function in all versions up to, and including, 5.9.3.6. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.26% | — | Jakir Hasan Blocks Post GridAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakir Hasan Blocks Post Grid blocks-post-grid allows DOM-Based XSS.This issue affects Blocks Post Grid: from n/a through <= 1.0.3. | |
| Aplazada | Media (6.5) | 0.37% | — | Dynamic Post Grid Elementor AddonAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maidul Dynamic Post Grid Elementor Addon dynamic-post-grid-elementor-addon allows DOM-Based XSS.This issue affects Dynamic Post Grid Elementor Addon: from n/a through <= 1.0.6. | |
| Modificada | Media (5.4) | 0.26% | — | Wpgrids Slicko | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Grids Slicko slicko-for-elementor allows DOM-Based XSS.This issue affects Slicko: from n/a through <= 1.2.0. | |
| Analizada | Media (4.3) | 0.36% | — | Netapp Storagegrid | 8/11/2024 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to a service crash. | |
| Aplazada | Alta (7.3) | 0.42% | — | YMC Filter AND GridsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in YMC Filter & Grids allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Filter & Grids: from n/a through 2.8.33. | |
| Aplazada | Media (5.4) | 0.33% | — | Radiustheme THE Post GridAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in RadiusTheme The Post Grid the-post-grid.This issue affects The Post Grid: from n/a through <= 7.7.4. | |
| Aplazada | Media (4.3) | 0.37% | — | Radiustheme THE Post GridAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in RadiusTheme The Post Grid the-post-grid.This issue affects The Post Grid: from n/a through <= 7.7.4. | |
| Aplazada | Media (6.5) | 0.34% | — | Radiustheme THE Post GridAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in RadiusTheme The Post Grid the-post-grid.This issue affects The Post Grid: from n/a through <= 7.7.4. | |
| Analizada | Alta (8.8) | 0.40% | — | Metagauss Profilegrid | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 5.8.7. | |
| Aplazada | Media (6.5) | 0.27% | — | Pickplugins Post GridAI | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Cross-Site Scripting (XSS).This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.2.93. | |
| Aplazada | Alta (7.2) | 0.69% | — | SogridAI | 26/10/2024 | 17/6/2026 | The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.6 via the 'tab' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files… | |
| Modificada | Media (6.5) | 0.32% | — | Metagauss Profilegrid | 21/10/2024 | 17/6/2026 | Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities.This issue affects ProfileGrid : from n/a through <= 5.9.3. | |
| Analizada | Media (4.3) | 0.36% | — | Smackcoders Sendgrid | 18/10/2024 | 17/6/2026 | The SendGrid for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wp_mailplus_clear_logs' function in all versions up to, and including, 1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the… | |
| Aplazada | Media (6.1) | 0.32% | — | I13websolution Video GridAI | 16/10/2024 | 17/6/2026 | The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute… | |
| Analizada | Alta (8.8) | 0.49% | — | Pickplugins Post Grid | 16/10/2024 | 17/6/2026 | The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with… | |
| Aplazada | Media (6.4) | 0.33% | — | WP Ultimate Post GridAI | 11/10/2024 | 17/6/2026 | The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpupg-grid-with-filters shortcode in all versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.27% | — | Pickplugins Post GridAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.2.89. | |
| Analizada | Media (4.8) | 0.31% | — | Radiustheme THE Post Grid | 30/9/2024 | 17/6/2026 | The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.4) | 0.35% | — | Metagauss Profilegrid | 26/9/2024 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without sufficient… |