Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.92% | — | Profilepress WP User AvatarAI | 31/8/2026 | 8/9/2026 | ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a… | |
| Aplazada | Alta (7.5) | 0.66% | — | Onedesigns ONE User AvatarAI | 28/8/2026 | 28/8/2026 | The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type validation in wp_handle_upload() called without a MIME allow-list, with… | |
| Aplazada | Media (6.5) | 0.33% | — | WP Social AvatarAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. | |
| Aplazada | Media (4.3) | 0.29% | — | Matteo Manna Simple User AvatarAI | 29/6/2026 | 8/7/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9. | |
| Analizada | Media (5.1) | 0.24% | — | Avatar Uploader Project Avatar Uploader | 10/5/2026 | 24/7/2026 | Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs with script payloads in the file parameter of avatar_uploader.pages.inc to execute arbitrary… | |
| Aplazada | Media (5.3) | 0.31% | — | Paul Bearne Author Avatars List BlockAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Author Avatars List/Block: from n/a through <= 2.1.25. | |
| Aplazada | Media (6.5) | 0.16% | — | Saad Iqbal User Avatar ReloadedAI | 16/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal User Avatar - Reloaded user-avatar-reloaded allows Stored XSS.This issue affects User Avatar - Reloaded: from n/a through <= 1.2.2. | |
| Aplazada | Media (6.5) | 0.21% | — | WpavatarAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 文派翻译(WP Chinese Translation) WPAvatar wpavatar allows Stored XSS.This issue affects WPAvatar: from n/a through <= 1.9.4. | |
| Aplazada | Media (4.3) | 0.26% | — | 10up Simple Local AvatarsAI | 12/8/2025 | 17/6/2026 | The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar… | |
| Aplazada | Media (4.3) | 0.28% | — | Wpeventmanager WP User Profile AvatarAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Profile Avatar: from n/a through <= 1.0.6. | |
| Aplazada | Alta (8.1) | 1.0% | — | Jenkins AvatarAI | 18/4/2025 | 17/6/2026 | The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 0.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can… | |
| Aplazada | Media (4.3) | 0.34% | — | Jenkins AvatarAI | 17/4/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Scott Taylor Avatar avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Avatar: from n/a through <= 0.1.4. | |
| Modificada | Alta (8.8) | 0.19% | — | Venugopal Comment Date AND Gravatar Remover | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Site Request Forgery.This issue affects Comment Date and Gravatar remover: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Cybio GravatarlocalcacheAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in cybio GravatarLocalCache gravatarlocalcache allows Cross Site Request Forgery.This issue affects GravatarLocalCache: from n/a through <= 1.1.2. | |
| Aplazada | Media (4.3) | 0.17% | — | WP User Profile AvatarAI | 16/1/2025 | 17/6/2026 | The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for unauthenticated attackers to update the plugins setting which… | |
| Aplazada | Media (6.5) | 0.23% | — | Paul Bearne Author AvatarsAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.23. | |
| Aplazada | Alta (7.1) | 0.44% | — | Enrico Cantori 3D Avatar User ProfileAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enrico Cantori 3D Avatar User Profile 3d-avatar-user-profile allows Reflected XSS.This issue affects 3D Avatar User Profile: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.3) | 0.34% | — | 10up Simple Local AvatarsAI | 16/11/2024 | 17/6/2026 | The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and including, 2.7.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear user… | |
| Aplazada | Media (6.5) | 0.26% | — | Paul Bearne Author Avatars List BlockAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.21. | |
| Analizada | Alta (8.8) | 0.21% | — | 10up Simple Local Avatars | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10. | |
| Analizada | Media (5.4) | 0.42% | — | Wpeventsmanager User Profile Avatar | 15/4/2024 | 17/6/2026 | The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.3) | 0.40% | — | Wp-eventmanager User Profile Avatar | 22/1/2024 | 17/6/2026 | The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar | |
| Modificada | Media (5.4) | 0.39% | — | Bearne Author Avatars List/block | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through 2.1.17. | |
| Modificada | Alta (8.8) | 0.32% | — | Petersterling ADD Local Avatar | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Add Local Avatar.This issue affects Add Local Avatar: from n/a through 12.1. | |
| Modificada | Media (6.1) | 0.41% | — | Enejbajgoric/gagansandhu/ctltdev User Avatar | 8/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions. |