Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 304 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.20% | — | Awesomesupport Awesome SupportAI | 1/10/2026 | 1/10/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.24% | — | Awesomesupport Awesome SupportAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions. | |
| Aplazada | Media (4.3) | 0.24% | — | Awesomesupport Awesome SupportAI | 9/9/2026 | 11/9/2026 | The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or… | |
| Aplazada | Media (5.3) | 0.44% | — | Awesomesupport Awesome SupportAI | 8/4/2026 | 25/7/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the authenticated user has permission to view the specific… | |
| Aplazada | Media (6.5) | 0.40% | — | Awesomesupport Awesome SupportAI | 16/1/2026 | 17/6/2026 | The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all versions up to, and including, 6.3.6. This is due to the 'wpas_do_mr_activate_user' function not verifying that a user has permission to modify other users' roles,… | |
| Aplazada | Alta (7.2) | 0.47% | — | Awesomesupport Awesome SupportAI | 22/9/2025 | 30/9/2026 | Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injection.This issue affects Awesome Support: from n/a through <= 6.3.5. | |
| Aplazada | Media (5.3) | 0.29% | — | Awesomesupport Awesome SupportAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6. | |
| Aplazada | Alta (7.5) | 0.65% | — | Awesomesupport Awesome SupportAI | 1/4/2025 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the… | |
| Aplazada | Media (6.5) | 0.60% | — | Awesomesupport Awesome SupportAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.3.1. | |
| Modificada | Media (6.5) | 0.55% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.7. | |
| Modificada | Media (5.4) | 0.48% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.10. | |
| Modificada | Media (5.4) | 0.48% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.4. | |
| Modificada | Alta (7.3) | 0.30% | — | Awesomesupport Awesome Support Wordpress Helpdesk & Support | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5. | |
| Modificada | Alta (8.8) | 0.30% | — | Getawesomesupport Awesome Support | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7. | |
| Modificada | Media (5.4) | 0.31% | — | Getawesomesupport Awesome Support | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.6. | |
| Modificada | Crítica (9.8) | 0.40% | — | Getawesomesupport Awesome Support | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7. | |
| Modificada | Media (5.3) | 0.40% | — | Getawesomesupport Awesome Support | 10/2/2024 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Modificada | Media (4.3) | 0.43% | — | Getawesomesupport Awesome Support | 10/2/2024 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level… | |
| Modificada | Alta (8.8) | 0.63% | — | Getawesomesupport Awesome Support | 10/2/2024 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Modificada | Alta (8.8) | 0.22% | — | Getawesomesupport Awesome Support | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.5. | |
| Modificada | Alta (8.8) | 0.25% | — | Getawesomesupport Awesome Support | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4. | |
| Modificada | Alta (8.1) | 0.66% | — | Getawesomesupport Awesome Support | 6/11/2023 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server. | |
| Modificada | Media (6.1) | 0.40% | — | Getawesomesupport Awesome Support | 6/11/2023 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (4.3) | 0.40% | — | Getawesomesupport Awesome Support | 6/11/2023 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission. | |
| Modificada | Media (6.5) | 0.75% | — | Getawesomesupport Awesome Support | 28/11/2022 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector |