Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (7.5) | 0.30% | — | Regularlabs Tabs Accordions PROAI | 28/9/2026 | 30/9/2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url attributes in Tabs & Accordions (Pro) 2.3.0 - 3.1.0 - Tabs & Accordions Pro accepts a url option for an item and writes it to a generated data-rlta-url attribute. The browser code passes that value to window.open() when the item is activated.… | |
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Tabs AND AccordionsAI | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API. The affected renderer places the alias inside a quoted JavaScript argument in an HTML onclick… | |
| Aplazada | Media (6.5) | 0.22% | — | AccordionAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions. | |
| Aplazada | Media (6.4) | 0.35% | — | Techearty Easy AccordionAI | 8/8/2026 | 12/8/2026 | The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, and including, 3.1.8. This is due to insufficient input sanitization and output escaping in the accordion_header_renderer() function, which emits the attacker-supplied tag… | |
| Aplazada | Media (6.4) | 0.33% | — | Techearty Easy AccordionAI | 16/7/2026 | 16/7/2026 | The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.15% | — | Oxilab AccordionsAI | 9/6/2026 | 23/7/2026 | The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2.3.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject… | |
| Aplazada | Alta (7.5) | 0.30% | — | Unboundstudio Accordion FAQAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ allows PHP Local File Inclusion. This issue affects Accordion FAQ: from n/a through 2.2.1. | |
| Aplazada | Alta (7.1) | 0.15% | — | Unboundstudio Accordion FAQAI | 2/6/2026 | 22/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS. This issue affects Accordion FAQ: from n/a through 2.2.1. | |
| Aplazada | Media (4.9) | 0.58% | — | Read More AccordionAI | 20/5/2026 | 24/7/2026 | The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.5.7. This is due to the use of esc_sql() without surrounding the value in quotes in an ORDER BY clause inside the getAllDataByLimit() and… | |
| Aplazada | Alta (8.8) | 1.6% | — | Read More AccordionAI | 20/5/2026 | 24/7/2026 | The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting which database tables can be written to during import and not properly validating the imported data. This makes it… | |
| Aplazada | Media (6.4) | 0.38% | — | Ultimate FAQ AccordionAI | 9/4/2026 | 17/6/2026 | The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the set_display_variables() function (View.FAQ.class.php, line 746), which… | |
| Aplazada | Media (5.4) | 0.28% | — | Accordion AND Accordion SliderAI | 14/2/2026 | 17/6/2026 | The Accordion and Accordion Slider plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.5. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'wp_aas_save_attachment_data' and 'wp_aas_get_attachment_edit_form'… | |
| Aplazada | Media (6.4) | 0.19% | — | Simple WP Colorfull AccordionAI | 14/2/2026 | 17/6/2026 | The Simple Wp colorfull Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in the 'accordion' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.24% | — | Yasir129 Turn Yoast SEO FAQ Block TO AccordionAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yasir129 Turn Yoast SEO FAQ Block to Accordion faq-schema-block-to-accordion allows Stored XSS.This issue affects Turn Yoast SEO FAQ Block to Accordion: from n/a through <= 1.0.6. | |
| Aplazada | Media (6.5) | 0.32% | — | Bplugins B AccordionAI | 23/1/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in bPlugins B Accordion b-accordion allows Retrieve Embedded Sensitive Data.This issue affects B Accordion: from n/a through <= 2.0.2. | |
| Aplazada | Alta (7.1) | 0.27% | — | Lambertgroup Accordion Slider PROAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Accordion Slider PRO accordion_slider_pro allows Reflected XSS.This issue affects Accordion Slider PRO: from n/a through <= 1.2. | |
| Aplazada | Media (4.3) | 0.26% | — | Responsive Accordion SliderAI | 14/1/2026 | 17/6/2026 | The Responsive Accordion Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'resp_accordion_silder_save_images' function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (5.9) | 0.17% | — | Themepoints Accordion Accordions-wpAI | 6/1/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accordion accordions-wp allows Stored XSS.This issue affects Accordion: from n/a through <= 3.0.3. | |
| Aplazada | Media (4.3) | 0.18% | — | Wpdiscover Accordion Slider GalleryAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in wpdiscover Accordion Slider Gallery accordion-slider-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider Gallery: from n/a through <= 2.7. | |
| Aplazada | Media (4.3) | 0.22% | — | Edmonparker Read More AccordionAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in edmon.parker Read More & Accordion expand-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Read More & Accordion: from n/a through <= 3.5.5.1. | |
| Aplazada | Media (6.4) | 0.18% | — | Smartwp Lightweight AccordionAI | 15/12/2025 | 17/6/2026 | The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `lightweight-accordion` shortcode in all versions up to, and including, 1.5.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.5) | 0.31% | — | Lambertgroup Accordion Slider PROAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Accordion Slider PRO accordion_slider_pro allows Blind SQL Injection.This issue affects Accordion Slider PRO: from n/a through <= 1.2. | |
| Aplazada | Media (6.5) | 0.15% | — | Bqworks Accordion SliderAI | 21/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bqworks Accordion Slider accordion-slider allows Stored XSS.This issue affects Accordion Slider: from n/a through <= 1.9.13. | |
| Aplazada | Media (6.5) | 0.32% | — | Pickplugins AccordionAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Accordion accordions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion: from n/a through <= 2.3.14. | |
| Aplazada | Alta (7.5) | 0.61% | — | Woocommerce Category AND Products Accordion PanelAI | 15/10/2025 | 17/6/2026 | The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via the 'categoryaccordionpanel' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute… |