Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | WpadvertsAI | 10/9/2026 | 10/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions. | |
| Aplazada | Alta (7.5) | 1.6% | — | WpadvertsAI | 18/8/2026 | 20/8/2026 | The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site… | |
| Aplazada | Alta (7.1) | 0.25% | — | WpadvertsAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | WpadvertsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions. | |
| Aplazada | Media (6.5) | 0.35% | — | Greg Winiarski WpadvertsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Greg Winiarski WPAdverts wpadverts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPAdverts: from n/a through <= 2.3.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Wpfactory AdvertsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Adverts adverts-click-tracker allows DOM-Based XSS.This issue affects Adverts: from n/a through <= 1.4. | |
| Aplazada | Media (6.5) | 0.17% | — | WpadvertsAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows DOM-Based XSS.This issue affects WPAdverts: from n/a through <= 2.2.5. | |
| Aplazada | Media (6.5) | 0.19% | — | WpadvertsAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows DOM-Based XSS.This issue affects WPAdverts: from n/a through <= 2.2.4. | |
| Aplazada | Media (6.5) | 0.21% | — | Greg Winiarski WpadvertsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows DOM-Based XSS.This issue affects WPAdverts: from n/a through <= 2.2.3. | |
| Aplazada | Alta (7.5) | 0.77% | — | Greg Winiarski WpadvertsAI | 7/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Greg Winiarski WPAdverts wpadverts allows PHP Local File Inclusion.This issue affects WPAdverts: from n/a through <= 2.2.2. | |
| Aplazada | Media (6.5) | 0.32% | — | Greg Winiarski WpadvertsAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows Stored XSS.This issue affects WPAdverts: from n/a through <= 2.2.1. | |
| Aplazada | Media (5.3) | 0.45% | — | Wpfactory AdvertsAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in WPFactory Adverts adverts-click-tracker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Adverts: from n/a through <= 1.4. | |
| Aplazada | Media (4.3) | 0.19% | — | WpadvertsAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Greg Winiarski WPAdverts wpadverts allows Cross Site Request Forgery.This issue affects WPAdverts: from n/a through <= 2.1.2. | |
| Aplazada | Media (6.1) | 0.59% | — | WpadvertsAI | 21/11/2024 | 17/6/2026 | The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.7. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.1) | 0.27% | — | Webcodin WP Visual AdvertsAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodin WP Visual Adverts wp-visual-adverts allows Reflected XSS.This issue affects WP Visual Adverts: from n/a through <= 2.3.0. | |
| Aplazada | Alta (7.2) | 0.39% | — | WpadvertsAI | 30/10/2024 | 17/6/2026 | The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's adverts_add shortcode in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Alta (7.5) | 3.7% | — | S3bubble-amazon-s3-html-5-video-with-adverts | 10/10/2019 | 17/6/2026 | The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter. |