Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | Yithemes Yith Woocommerce Ajax SearchAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions. | |
| Aplazada | Crítica (9.8) | 0.85% | — | Ajax Search LiteAI | 7/8/2026 | 26/8/2026 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Ajax Search LiteAI | 6/8/2026 | 12/8/2026 | Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. | |
| Aplazada | Media (5.5) | 0.24% | — | Wpdreams Ajax Search LiteAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.This issue affects Ajax Search Lite: from n/a through <= 4.13.3. | |
| Aplazada | Media (5.3) | 0.30% | — | Ajax Search LiteAI | 28/8/2025 | 17/6/2026 | The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in its AJAX search handler in all versions up to, and including, 4.13.1. This makes it possible for unauthenticated attackers to issue repeated AJAX requests to leak the content of any protected post in… | |
| Aplazada | Media (5.3) | 0.24% | — | Damian Gora Fibosearch Ajax-search-for-woocommerceAI | 12/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FiboSearch: from n/a through <= 1.32.1. | |
| Analizada | Media (4.8) | 0.38% | — | Wp-dreams Ajax Search | 15/5/2025 | 17/6/2026 | The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.9) | 0.29% | — | Lavacode Lava Ajax SearchAI | 11/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax Search lava-ajax-search allows Stored XSS.This issue affects Lava Ajax Search: from n/a through <= 1.1.9. | |
| Analizada | Baja (3.5) | 0.41% | — | Wp-dreams Ajax Search | 21/2/2025 | 17/6/2026 | The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.9) | 0.39% | — | Dreamvention Live Ajax Search FreeAIOpencartAI | 8/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Dreamvention Live AJAX Search Free up to 1.0.6 on OpenCart. Affected by this issue is the function searchresults/search of the file /?route=extension/live_search/module/live_search.searchresults. The manipulation of the argument keyword leads to sql… | |
| Analizada | Media (4.7) | 0.42% | — | Wp-dreams Ajax Search | 12/12/2024 | 17/6/2026 | The Ajax Search Lite WordPress plugin before 4.12.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Crítica (9.3) | 0.41% | — | Yithemes Yith Woocommerce Ajax SearchAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITHEMES YITH WooCommerce Ajax Search yith-woocommerce-ajax-search.This issue affects YITH WooCommerce Ajax Search: from n/a through <= 2.8.0. | |
| Analizada | Media (5.4) | 0.33% | — | Yithemes Yith Woocommerce Ajax Search | 23/9/2024 | 17/6/2026 | YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbitrary scripts. | |
| Aplazada | Media (5.3) | 0.42% | — | Relevanssi Live Ajax SearchAI | 28/8/2024 | 17/6/2026 | The Relevanssi Live Ajax Search plugin for WordPress is vulnerable to argument injection in all versions up to, and including, 2.4. This is due to insufficient validation of input supplied via POST data in the 'search' function. This makes it possible for unauthenticated attackers to inject arbitrary arguments into a… | |
| Analizada | Media (4.8) | 0.39% | — | Wp-dreams Ajax Search | 6/8/2024 | 17/6/2026 | The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks. | |
| Modificada | Media (6.1) | 1.0% | — | Yithemes Yith Woocommerce Ajax Search | 24/5/2024 | 17/6/2026 | The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parameter in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Media (6.1) | 0.20% | — | Wp-dreams Ajax Search | 29/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ernest Marcinko Ajax Search Lite allows Reflected XSS.This issue affects Ajax Search Lite: from n/a through 4.11.4. | |
| Modificada | Media (6.1) | 0.46% | — | Wp-dreams Ajax Search | 24/4/2023 | 17/6/2026 | The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.49% | — | Wp-dreams Ajax Search | 24/4/2023 | 17/6/2026 | The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.5) | 0.55% | — | Ajax Search Project Ajax Search | 15/3/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions. | |
| Modificada | Media (5.3) | 1.9% | — | Searchwp Live Ajax Search | 15/8/2022 | 17/6/2026 | The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. |