Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
329 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.31% | — | WEN Themes WEN Responsive ColumnsAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Responsive Columns allows Stored XSS.This issue affects WEN Responsive Columns: from n/a through 1.3.2. | |
| Analizada | Media (6.1) | 0.49% | — | Bdwm Responsive Gallery Grid | 9/4/2024 | 17/6/2026 | The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (6.5) | 0.33% | — | Wppdf Responsive FlipbookAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wppdf.Org Responsive flipbook allows Stored XSS.This issue affects Responsive flipbook: from n/a through 1.0.0. | |
| Aplazada | Alta (7.1) | 0.38% | — | Creative-solutions Creative Image Slider - Responsive Slider PluginAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative Solutions Creative Image Slider – Responsive Slider Plugin allows Reflected XSS.This issue affects Creative Image Slider – Responsive Slider Plugin: from n/a through 2.1.3. | |
| Modificada | Alta (8.8) | 0.58% | — | I13websolution WP Responsive Tabs | 29/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17. | |
| Aplazada | Alta (7.5) | 0.65% | — | ResponsiveAI | 29/3/2024 | 17/6/2026 | The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_footer_text_callback function in all versions up to, and including, 5.0.2. This makes it possible for unauthenticated attackers to inject arbitrary HTML content into the site's footer. | |
| Analizada | Media (5.4) | 0.40% | — | Wpdarko Responsive Pricing Table | 18/3/2024 | 17/6/2026 | The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a page/post where the related shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.82% | — | Awplife Slider Responsive Slideshow | 1/3/2024 | 17/6/2026 | The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8 via deserialization of untrusted input to the awl_slider_responsive_shortcode function. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.23% | — | Jtrt Responsive Tables Project Jtrt Responsive Tables | 21/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in John Tendik JTRT Responsive Tables.This issue affects JTRT Responsive Tables: from n/a through 4.1.9. | |
| Modificada | Alta (8.8) | 0.56% | — | Kutethemes Ovic Responsive Wpbakery | 8/1/2024 | 17/6/2026 | The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_role'. It also unserializes user input in the process, which may… | |
| Modificada | Media (5.4) | 0.38% | — | Dfactory Responsive Lightbox | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dFactory Responsive Lightbox & Gallery allows Stored XSS.This issue affects Responsive Lightbox & Gallery: from n/a through 2.4.5. | |
| Modificada | Media (6.1) | 0.39% | — | Michaeluno Responsive Column Widgets | 7/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Michael Uno (miunosoft) Responsive Column Widgets.This issue affects Responsive Column Widgets: from n/a through 1.2.7. | |
| Modificada | Media (6.1) | 0.41% | — | Michaeluno Responsive Column Widgets | 14/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Uno (miunosoft) Responsive Column Widgets plugin <= 1.2.7 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Simonpedge Slide Anything-responsive Content/html Slider AND Carousel | 7/11/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Wpdarko Responsive Pricing Table | 6/11/2023 | 17/6/2026 | The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 0.68% | — | Weblizar Responsive Coming Soon & Maintenance Mode | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar Coming Soon Page – Responsive Coming Soon & Maintenance Mode allows SQL Injection.This issue affects Coming Soon Page – Responsive Coming Soon & Maintenance Mode: from n/a through 1.5.9. | |
| Modificada | Media (4.8) | 0.48% | — | Deanoakley Photospace Responsive Gallery | 20/10/2023 | 17/6/2026 | The Photospace Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘psres_button_size’ parameter in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions… | |
| Modificada | Alta (8.8) | 0.25% | — | Bdwm Responsive Gallery Grid | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jules Colle, BDWM Responsive Gallery Grid plugin <= 2.3.10 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Wponlinesupport WP Responsive Header Image Slider | 3/10/2023 | 17/6/2026 | The WP Responsive header image slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sp_responsiveslider' shortcode in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Media (5.4) | 0.51% | — | Stefanoai Widget Responsive FOR Youtube | 20/9/2023 | 17/6/2026 | The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortcode in versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution WP Responsive Tabs Horizontal Vertical AND Accordion Tabs | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs plugin <= 1.1.15 versions. | |
| Modificada | Crítica (9.8) | 2.3% | 💥 PoC | Tecrail Responsive Filemanager | 28/6/2023 | 17/6/2026 | In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE. | |
| Modificada | Alta (7.2) | 0.85% | — | Wpwox Responsive CSS Editor | 27/6/2023 | 17/6/2026 | The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admin. | |
| Modificada | Media (5.4) | 0.44% | — | Responsive Tabs FOR Wpbakery Page Builder Project Responsive Tabs FOR Wpbakery Page Builder | 19/6/2023 | 17/6/2026 | The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored… | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution WP Responsive Tabs | 9/6/2023 | 17/6/2026 | The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… |