Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.5) | — | — | Fluent Affiliate PROAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Redefiningtheweb Affiliate PROAI | 24/8/2026 | 24/8/2026 | Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. | |
| Aplazada | Baja (3.8) | 0.26% | — | Post Affiliate PROAI | 21/3/2026 | 17/6/2026 | The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.28.0. This makes it possible for authenticated attackers, with Administrator-level access, to make web requests to initiate arbitrary outbound requests from the application and read the… | |
| Aplazada | Media (4.8) | 0.20% | — | Redefiningtheweb Affiliate PROAI | 1/2/2026 | 17/6/2026 | Affiliate Pro 1.7 contains multiple reflected cross-site scripting vulnerabilities in the index module's input fields. Attackers can inject malicious scripts through fullname, username, and email parameters to execute client-side attacks and manipulate browser requests. | |
| Analizada | Crítica (9.8) | 0.58% | — | Redefiningtheweb Affiliate PRO | 1/10/2024 | 17/6/2026 | The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible… | |
| Analizada | Media (6.1) | 0.46% | — | Slicewp Affiliate Program Suite | 13/9/2024 | 17/6/2026 | The WordPress Affiliates Plugin — SliceWP Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.20. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (4.8) | 0.37% | — | Qualityunit Post Affiliate PRO | 3/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QualityUnit Post Affiliate Pro plugin <= 1.25.0 versions. | |
| Modificada | Media (4) | 1.7% | — | Peter Pokrivcak Post Affiliate PRO | 27/6/2012 | 16/6/2026 | Unspecified vulnerability in the Post Affiliate Pro (PAP) module for Drupal allows remote authenticated users to read the commissions of other users via unknown attack vectors. | |
| Modificada | Media (4.3) | 1.8% | — | Peter Pokrivcak Post Affiliate PRO | 27/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Post Affiliate Pro (PAP) module for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to user registration. | |
| Modificada | Media (6.8) | 1.1% | — | Qualityunit Post Affiliate PRO | 17/12/2008 | 16/6/2026 | SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 3 and 3.1.4 allows remote attackers to execute arbitrary SQL commands via the umprof_status parameter. | |
| Modificada | Media (6.5) | 2.1% | — | Qualityunit Post Affiliate PRO | 18/10/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in Post Affiliate Pro 2.0 allows remote authenticated users to read and possibly execute arbitrary local files via a .. (dot dot) in the md parameter. | |
| Modificada | Media (5) | 1.3% | — | Post Affiliate PRO | 30/11/2005 | 16/6/2026 | merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Post Affiliate PRO | 30/11/2005 | 16/6/2026 | SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter. |