Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.28% | — | Codeastro Membership Management System | 2/9/2024 | 17/6/2026 | CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS. | |
| Modificada | Crítica (10) | 0.54% | — | Wpindeed Ultimate Membership PRO | 19/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Modificada | Crítica (9.8) | 0.55% | — | Wpindeed Ultimate Membership PRO | 19/8/2024 | 17/6/2026 | Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpindeed Ultimate Membership PROAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Aplazada | Media (6.1) | 0.49% | — | Opal MembershipAI | 12/8/2024 | 17/6/2026 | The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (4.3) | 0.59% | — | Opal MembershipAI | 12/8/2024 | 17/6/2026 | The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticated attackers, with subscriber-level access and above, to view… | |
| Analizada | Alta (8.8) | 0.33% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php. | |
| Analizada | Alta (7.6) | 1.1% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter. | |
| Analizada | Crítica (9.8) | 1.0% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters. | |
| Analizada | Crítica (9.8) | 1.2% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Modificada | Media (6.5) | 0.52% | — | Strangerstudios Paid Memberships PRO | 30/7/2024 | 17/6/2026 | The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector. | |
| Analizada | Media (4.9) | 0.56% | — | Strangerstudios Paid Memberships PRO | 30/7/2024 | 17/6/2026 | The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site. | |
| Aplazada | Media (6.5) | 0.34% | — | Wpdarko Team MembersAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Members allows Stored XSS.This issue affects Team Members: from n/a through 5.3.3. | |
| Modificada | Alta (7.2) | 0.74% | — | Strangerstudios Paid Memberships PRO | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5. | |
| Analizada | Alta (8.8) | 0.48% | — | Strangerstudios Paid Memberships PRO | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3. | |
| Aplazada | Alta (8.2) | 0.44% | — | Paidmembershipspro Ccbill GatewayAI | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Paid Memberships Pro Paid Memberships Pro CCBill Gateway.This issue affects Paid Memberships Pro CCBill Gateway: from n/a through 0.3. | |
| Modificada | Media (5.4) | 0.22% | — | Strangerstudios Paid Memberships PRO | 19/6/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated… | |
| Modificada | Media (5.3) | 0.44% | — | Membersonly Buddypress Members Only | 6/6/2024 | 17/6/2026 | The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "All Other Sections On Your Site Will be Opened to Guest" feature (when unset) and… | |
| Analizada | Crítica (9.8) | 0.77% | — | Simple-membership-plugin Simple Membership | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4. | |
| Analizada | Alta (8.8) | 0.91% | — | Simple-membership-plugin Simple Membership | 17/5/2024 | 17/6/2026 | Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4. | |
| Modificada | Media (5.4) | 0.43% | — | Simple-membership-plugin Simple Membership | 14/5/2024 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (4.3) | 0.30% | — | Strangerstudios Paid Memberships PRO | 2/5/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the pmpro_update_level_group_order() function. This makes it… | |
| Aplazada | Media (5.3) | 0.50% | — | Butlerblog Wp-membersAI | 26/4/2024 | 17/6/2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.4.9.3 due to the plugin uploading user supplied files to a publicly accessible directory in wp-content without any restrictions. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.4) | 0.34% | — | Simple-membership-plugin Simple Membership | 25/4/2024 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.24% | — | Strangerstudios Paid Memberships PRO | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. |