Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.33% | — | Anycomment.io | 15/1/2026 | 17/6/2026 | Cross Site Scripting vulnerability in Anycomment anycomment.io 0.4.4 allows a remote attacker to execute arbitrary code via the Anycomment comment section | |
| Aplazada | Media (4.3) | 0.29% | — | Bologer AnycommentAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in Alexander AnyComment anycomment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyComment: from n/a through <= 0.3.6. | |
| Aplazada | Alta (7.5) | 0.43% | — | Bologer AnycommentAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alexander AnyComment anycomment allows PHP Local File Inclusion.This issue affects AnyComment: from n/a through <= 0.3.6. | |
| Aplazada | Alta (8.5) | 0.42% | — | Bologer AnycommentAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComment anycomment allows SQL Injection.This issue affects AnyComment: from n/a through <= 0.3.6. | |
| Modificada | Baja (3.1) | 0.49% | — | Bologer Anycomment | 21/2/2022 | 17/6/2026 | The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users | |
| Modificada | Alta (8.8) | 0.65% | — | Bologer Anycomment | 21/2/2022 | 17/6/2026 | The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack | |
| Modificada | Media (6.1) | 2.2% | — | Bologer Anycomment | 17/1/2022 | 17/6/2026 | The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature. | |
| Modificada | Media (6.1) | 0.91% | — | Bologer Anycomment | 27/8/2019 | 17/6/2026 | The anycomment plugin before 0.0.33 for WordPress has XSS. |