Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.39% | — | Gopiplus Popup Contact Form | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Popup contact form plugin <= 7.1 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Gopiplus Popup Contact Form | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Popup contact form plugin <= 7.1 versions. | |
| Modificada | Media (4.8) | 0.45% | — | Gopiplus Onclick Show Popup | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Onclick show popup plugin <= 8.1 versions. | |
| Modificada | Media (4.8) | 0.45% | — | Sygnoos Popup Builder | 25/9/2023 | 17/6/2026 | The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Crítica (9.8) | 0.99% | — | Planned Popup Project Planned Popup | 21/9/2023 | 17/6/2026 | SQL injection vulnerability in Prestashop opartplannedpopup 1.4.11 and earlier allows remote attackers to run arbitrary SQL commands via OpartPlannedPopupModuleFrontController::prepareHook() method. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Fieldthemes Fieldpopupnewsletter | 8/9/2023 | 17/6/2026 | FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php. | |
| Modificada | Media (4.8) | 0.36% | — | Gopiplus Wp-tell-a-friend-popup-form | 4/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy wp tell a friend popup form plugin <= 7.1 versions. | |
| Modificada | Media (6.1) | 0.37% | — | Bbsetheme BBS E-popup | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in BBS e-Theme BBS e-Popup plugin <= 2.4.5 versions. | |
| Modificada | Media (6.1) | 0.41% | — | I13websolution Email Subscription Popup | 14/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <= 1.2.16 versions. | |
| Modificada | Media (6.1) | 0.36% | — | Arscode Ninja Popups | 10/8/2023 | 17/6/2026 | Unauth. Open Redirect vulnerability in Arscode Ninja Popups plugin <= 4.7.5 versions. | |
| Modificada | Media (4.3) | 0.61% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+6 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.5) | 0.69% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+7 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,… | |
| Modificada | Media (6.1) | 0.38% | — | Crudlab Jazz Popups | 18/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions. | |
| Modificada | Crítica (9.8) | 1.5% | — | Supsystic Popup | 17/7/2023 | 17/6/2026 | The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype. | |
| Modificada | Media (4.3) | 0.39% | — | Ashstonestudios Advanced Popups | 12/7/2023 | 17/6/2026 | The Advanced Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the metabox_popup_save() function. This makes it possible for unauthenticated attackers to save meta tags via a forged request granted… | |
| Modificada | Media (6.1) | 0.41% | — | Ays-pro Popup BOX | 21/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin <= 3.4.4 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Wow-company Bubble MenuWow-company Button GeneratorWow-company Calculator-builderWow-company Counter BOX+8 | 12/6/2023 | 17/6/2026 | The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before… | |
| Modificada | Media (4.6) | 0.70% | — | Xootix Login/signup Popup | 7/6/2023 | 17/6/2026 | The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin settings that execute if they can… | |
| Modificada | Alta (8.8) | 0.39% | — | Newsletter Popup Project Newsletter Popup | 30/5/2023 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks as the wp_newsletter_show_localrecord page is not protected with a nonce. | |
| Modificada | Media (6.1) | 0.51% | — | Newsletter Popup Project Newsletter Popup | 30/5/2023 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.36% | — | Wpmanage UJI Popup | 16/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPmanage Uji Popup plugin <= 1.4.3 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Simple Popup Project Simple Popup | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb ur Rehman Simple PopUp plugin <= 1.8.6 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Timersys WP Popups | 8/5/2023 | 17/6/2026 | The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page shortcode before outputting it back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. This is due to… | |
| Modificada | Alta (7.2) | 0.96% | — | Zyrex Popup | 2/5/2023 | 17/6/2026 | The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (such as an Administrator) to upload arbitrary files, even when modifying the file system is disallowed, such as in a multisite install. | |
| Modificada | Media (4.8) | 0.39% | — | WP Super Popup Project WP Super Popup | 24/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Plugins Pro WP Super Popup plugin <= 1.1.2 versions. |