Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2494▼ 451 respecto a la semana anterior
Críticas / altas1280▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.21% | — | Product Badge Label Countdown Timer FOR WoocommerceAI | 23/9/2026 | 23/9/2026 | The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products. | |
| Aplazada | Media (6.4) | 0.33% | — | Wpclever WPC Badge ManagementAI | 29/7/2026 | 30/7/2026 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (6.1) | 0.37% | — | NS Product Icon BadgeAI | 27/5/2026 | 17/6/2026 | The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute… | |
| Aplazada | Media (5.5) | 0.21% | — | Wpclever WPC Badge ManagementAI | 13/5/2026 | 30/9/2026 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.21% | — | Newclarity Dmca Protection BadgeAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in NewClarity DMCA Protection Badge dmca-badge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DMCA Protection Badge: from n/a through <= 2.2.0. | |
| Aplazada | Media (6.5) | 0.20% | — | Sertifier Certificates Open BadgesAI | 6/11/2025 | 17/6/2026 | Missing Authorization vulnerability in sertifier Sertifier Certificate & Badge Maker sertifier-certificates-open-badges allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sertifier Certificate & Badge Maker: from n/a through <= 1.21. | |
| Aplazada | Media (4.3) | 0.11% | — | Sertifier Certificate AND Badge Maker FOR Wordpress Tutor LMSAI | 23/8/2025 | 17/6/2026 | The Sertifier Certificate & Badge Maker for WordPress – Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.19. This is due to missing or incorrect nonce validation on the 'sertifier_settings' page. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.4) | 0.23% | — | Live Stream BadgerAI | 19/7/2025 | 17/6/2026 | The Live Stream Badger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livestream' shortcode in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.8) | 0.27% | — | Danielpowney Badgearoo | 15/5/2025 | 17/6/2026 | The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (6.1) | 0.33% | — | Danielpowney Badgearoo | 15/5/2025 | 17/6/2026 | The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (4.9) | 0.27% | — | Accredible Certificates Open BadgesAI | 10/4/2025 | 17/6/2026 | The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Media (6.5) | 0.36% | — | Draftpress Team Follow US BadgesAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DraftPress Team Follow Us Badges wpsite-follow-us-badges allows Stored XSS.This issue affects Follow Us Badges: from n/a through <= 3.1.11. | |
| Analizada | Media (4.1) | 0.34% | — | Acowebs Product Labels FOR Woocommerce (sale Badges) | 25/3/2025 | 17/6/2026 | The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Analizada | Media (4.1) | 0.41% | — | Acowebs Product Labels FOR Woocommerce (sale Badges) | 25/3/2025 | 17/6/2026 | The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Aplazada | Alta (8.1) | 0.89% | — | Dzeriho Improved Sale Badges Free VersionAI | 22/1/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dzeriho Improved Sale Badges – Free Version improved-sale-badges-free-version allows PHP Local File Inclusion.This issue affects Improved Sale Badges – Free Version: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.3) | 0.30% | — | Wikimedia MediawikiAIWikimedia Openbadges ExtensionAI | 14/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - OpenBadges Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - OpenBadges Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X… | |
| Aplazada | Media (4.3) | 0.44% | — | BadgeosAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in LearningTimes BadgeOS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BadgeOS: from n/a through 3.7.1.6. | |
| Aplazada | Alta (7.1) | 0.15% | — | Irish Cathal OUT OF Stock BadgeAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Irish_Cathal Out Of Stock Badge out-of-stock-badge allows Cross Site Request Forgery.This issue affects Out Of Stock Badge: from n/a through <= 2.0. | |
| Aplazada | Alta (7.6) | 0.52% | — | ABW Badger-databaseAI | 17/6/2024 | 17/6/2026 | A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm. | |
| Modificada | Alta (8.8) | 0.32% | — | Wpclever WPC Badge Management FOR Woocommerce | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPClever WPC Badge Management for WooCommerce.This issue affects WPC Badge Management for WooCommerce: from n/a through 2.4.0. | |
| Aplazada | Media (6.4) | 0.32% | — | Follow US BadgesAI | 2/5/2024 | 17/6/2026 | The Follow Us Badges plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsite_follow_us_badges shortcode in all versions up to, and including, 3.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.1) | 0.67% | — | Badgermeter Monitool | 12/3/2024 | 17/6/2026 | Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows a remote attacker to send a specially crafted javascript payload to an authenticated user and partially hijack their browser session. | |
| Analizada | Media (6.5) | 1.0% | — | Badgermeter Monitool | 12/3/2024 | 17/6/2026 | Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows an authenticated attacker to retrieve any file from the device using the download-file functionality. | |
| Analizada | Media (5.5) | 0.49% | — | Badgermeter Monitool | 12/3/2024 | 17/6/2026 | Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials. | |
| Analizada | Alta (7.5) | 2.2% | — | Badgermeter Monitool | 12/3/2024 | 17/6/2026 | SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_username parameter and retrieve the information stored in the database. |