Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.40% | — | Vrinsoft CSV Product Import Export FOR WoocommerceAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vrinsoft CSV Product Import Export for WooCommerce csv-wc-product-import-export.This issue affects CSV Product Import Export for WooCommerce: from n/a through <= 1.0.0. | |
| Aplazada | Crítica (9.9) | 0.58% | — | Themegrill Demo ImporterAI | 16/10/2024 | 17/6/2026 | The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named… | |
| Aplazada | Media (6.5) | 1.1% | 💥 PoC | Comments Import ExportAI | 11/10/2024 | 17/6/2026 | The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to read the… | |
| Aplazada | Media (6.4) | 0.33% | — | Mediawiki ImportdumpAI | 9/10/2024 | 17/6/2026 | ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the same actor ID as someone on the central wiki, the user on the other wiki can act as if they're the… | |
| Aplazada | Media (6) | 0.41% | — | Mediawiki ImportdumpAI | 9/10/2024 | 17/6/2026 | ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface strings of a wiki (typically administrators and interface admins) can embed XSS payloads in the messages for dates, and thus XSS anyone who views Special:RequestImportQueue. This issue has been patched… | |
| Analizada | Media (5.4) | 0.32% | — | Sigmadevs Easy Demo Importer | 4/10/2024 | 17/6/2026 | The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.32% | — | Kraftplugins Demo Importer Plus | 2/10/2024 | 17/6/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Analizada | Media (6.6) | 0.74% | — | Fastlinemedia Customizer Export/import | 7/9/2024 | 17/6/2026 | The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions up to, and including, 0.9.7. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files… | |
| Aplazada | Alta (7.5) | 0.42% | — | Codection Import AND Export Users AND CustomersAI | 13/8/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.8. | |
| Analizada | Alta (7.5) | 0.39% | — | Olivethemes Olive ONE Click Demo Import | 13/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Olive One Click Demo Import: from n/a through 1.1.2. | |
| Modificada | Media (6.4) | 0.25% | — | Json-content-importer Json Content Importer | 22/7/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5.6. | |
| Aplazada | Media (4.3) | 0.32% | — | Mekshq Meks Video ImporterAI | 18/7/2024 | 17/6/2026 | The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capability check on the ajax_save_settings function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the… | |
| Aplazada | Crítica (9.1) | 0.49% | — | Spreadsheetconverter Import Spreadsheets From Microsoft ExcelAI | 12/7/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.4. | |
| Modificada | Media (6.5) | 0.50% | — | Wpneuron Sparkle Demo Importer | 22/6/2024 | 17/6/2026 | The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Aplazada | Media (5.4) | 0.37% | — | Codection Import AND Export Users AND CustomersAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.5. | |
| Modificada | Media (6.5) | 0.53% | — | Ovic Importer Project Ovic Importer | 10/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ovic Team Ovic Importer allows Path Traversal.This issue affects Ovic Importer: from n/a through 1.6.3. | |
| Aplazada | Alta (7.6) | 0.33% | — | Crafthemes Demo ImportAI | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Crafthemes Crafthemes Demo Import crafthemes-demo-import allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crafthemes Demo Import: from n/a through <= 3.3. | |
| Modificada | Alta (7.5) | 0.29% | — | Olivethemes Olive ONE Click Demo Import | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. | |
| Analizada | Media (5.3) | 0.32% | — | Codection Import AND Export Users AND Customers | 8/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6. | |
| Aplazada | Media (4.4) | 0.24% | — | Webtoffee Order Export AND Order Import FOR WoocommerceAI | 16/5/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.9. | |
| Aplazada | Media (4.4) | 0.29% | — | Webtoffee Import AND Export Users AND CustomersAI | 15/5/2024 | 17/6/2026 | The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Media (4.4) | 0.26% | — | Codection Import AND Export Users AND CustomersAI | 15/5/2024 | 17/6/2026 | The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access… | |
| Modificada | Alta (7.2) | 0.50% | — | Ocdi ONE Click Demo Import | 14/5/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0. | |
| Aplazada | Media (4.3) | 0.43% | — | Webtoffee Import AND Export Users AND CustomersAI | 4/5/2024 | 17/6/2026 | The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.18% | — | Famethemes Fametheme Demo ImporterAI | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FameThemes FameTheme Demo Importer.This issue affects FameTheme Demo Importer: from n/a through 1.1.5. |