Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

379 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.40%—Vrinsoft CSV Product Import Export FOR WoocommerceAI17/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vrinsoft CSV Product Import Export for WooCommerce csv-wc-product-import-export.This issue affects CSV Product Import Export for WooCommerce: from n/a through <= 1.0.0.
AplazadaCrítica (9.9)0.58%—Themegrill Demo ImporterAI16/10/202417/6/2026
The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named…
AplazadaMedia (6.5)1.1%💥 PoCComments Import ExportAI11/10/202417/6/2026
The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to read the…
AplazadaMedia (6.4)0.33%—Mediawiki ImportdumpAI9/10/202417/6/2026
ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the same actor ID as someone on the central wiki, the user on the other wiki can act as if they're the…
AplazadaMedia (6)0.41%—Mediawiki ImportdumpAI9/10/202417/6/2026
ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface strings of a wiki (typically administrators and interface admins) can embed XSS payloads in the messages for dates, and thus XSS anyone who views Special:RequestImportQueue. This issue has been patched…
AnalizadaMedia (5.4)0.32%—Sigmadevs Easy Demo Importer4/10/202417/6/2026
The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaMedia (5.4)0.32%—Kraftplugins Demo Importer Plus2/10/202417/6/2026
The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…
AnalizadaMedia (6.6)0.74%—Fastlinemedia Customizer Export/import7/9/202417/6/2026
The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions up to, and including, 0.9.7. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files…
AplazadaAlta (7.5)0.42%—Codection Import AND Export Users AND CustomersAI13/8/202417/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.8.
AnalizadaAlta (7.5)0.39%—Olivethemes Olive ONE Click Demo Import13/8/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Olive One Click Demo Import: from n/a through 1.1.2.
ModificadaMedia (6.4)0.25%—Json-content-importer Json Content Importer22/7/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5.6.
AplazadaMedia (4.3)0.32%—Mekshq Meks Video ImporterAI18/7/202417/6/2026
The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capability check on the ajax_save_settings function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the…
AplazadaCrítica (9.1)0.49%—Spreadsheetconverter Import Spreadsheets From Microsoft ExcelAI12/7/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.4.
ModificadaMedia (6.5)0.50%—Wpneuron Sparkle Demo Importer22/6/202417/6/2026
The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…
AplazadaMedia (5.4)0.37%—Codection Import AND Export Users AND CustomersAI11/6/202417/6/2026
Missing Authorization vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.5.
ModificadaMedia (6.5)0.53%—Ovic Importer Project Ovic Importer10/6/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ovic Team Ovic Importer allows Path Traversal.This issue affects Ovic Importer: from n/a through 1.6.3.
AplazadaAlta (7.6)0.33%—Crafthemes Demo ImportAI10/6/202417/6/2026
Missing Authorization vulnerability in Crafthemes Crafthemes Demo Import crafthemes-demo-import allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crafthemes Demo Import: from n/a through <= 3.3.
ModificadaAlta (7.5)0.29%—Olivethemes Olive ONE Click Demo Import9/6/202417/6/2026
Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
AnalizadaMedia (5.3)0.32%—Codection Import AND Export Users AND Customers8/6/202417/6/2026
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
AplazadaMedia (4.4)0.24%—Webtoffee Order Export AND Order Import FOR WoocommerceAI16/5/202417/6/2026
Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.9.
AplazadaMedia (4.4)0.29%—Webtoffee Import AND Export Users AND CustomersAI15/5/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AplazadaMedia (4.4)0.26%—Codection Import AND Export Users AND CustomersAI15/5/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access…
ModificadaAlta (7.2)0.50%—Ocdi ONE Click Demo Import14/5/202417/6/2026
Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0.
AplazadaMedia (4.3)0.43%—Webtoffee Import AND Export Users AND CustomersAI4/5/202417/6/2026
The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.18%—Famethemes Fametheme Demo ImporterAI26/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in FameThemes FameTheme Demo Importer.This issue affects FameTheme Demo Importer: from n/a through 1.1.5.