Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.86% | — | AdrotateAI | 24/6/2026 | 25/6/2026 | The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code… | |
| Aplazada | Alta (7.2) | 0.96% | — | AdrotateAI | 20/8/2024 | 17/6/2026 | The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.29% | — | Adrotate Banner Manager Project Adrotate Banner Manager | 30/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin <= 5.9 on WordPress. | |
| Modificada | Media (4.8) | 0.60% | — | Ajdg Adrotate | 2/5/2022 | 17/6/2026 | The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.8) | 0.60% | — | Ajdg Adrotate | 2/5/2022 | 17/6/2026 | The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Alta (7.2) | 1.3% | — | Adrotate Project Adrotate | 7/3/2022 | 17/6/2026 | The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection | |
| Modificada | Media (5.5) | 1.2% | — | Ajdg Adrotate | 18/3/2021 | 17/6/2026 | Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user. | |
| Modificada | Alta (7.2) | 1.5% | — | Ajdg Adrotate | 23/7/2019 | 17/6/2026 | The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection. | |
| Modificada | Alta (7.5) | 5.7% | — | Adrotateplugin Adrotate | 27/2/2014 | 17/6/2026 | SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free plugin 3.9 through 3.9.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter. | |
| Modificada | Alta (7.5) | 2.9% | — | Adrotateplugin Adrotate | 2/12/2011 | 16/6/2026 | SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL). | |
| Modificada | Alta (7.5) | 2.1% | — | LES Vanbrunt Adrotate PRO | 23/12/2001 | 16/6/2026 | get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack. |