Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.18% | — | Bootstrapped WP Recipe MakerAI | 23/9/2026 | 23/9/2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes. | |
| Aplazada | Alta (8.2) | 0.24% | — | Bootstrapped WP Recipe MakerAI | 23/9/2026 | 23/9/2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from… | |
| Aplazada | Media (4.3) | 0.18% | — | Bootstrapped WP Recipe MakerAI | 23/9/2026 | 23/9/2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists. | |
| Aplazada | Media (4.3) | 0.18% | — | Bootstrapped WP Recipe MakerAI | 23/9/2026 | 23/9/2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes. | |
| Aplazada | Crítica (9.1) | 0.68% | — | Bootstrapped WP Recipe MakerAI | 19/9/2026 | 21/9/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the… | |
| Aplazada | Media (5.4) | 0.24% | — | Bootstrapped WP Recipe MakerAI | 18/9/2026 | 18/9/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.6) | 0.39% | — | Areoi ALL Bootstrap BlocksAI | 18/9/2026 | 18/9/2026 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file… | |
| Aplazada | Media (6.8) | 0.43% | — | Areoi ALL Bootstrap BlocksAI | 18/9/2026 | 18/9/2026 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed. | |
| Aplazada | Media (4.3) | 0.37% | — | Bootstrapped WP Recipe MakerAI | 9/9/2026 | 9/9/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.4) | 0.26% | — | Bootstrapped WP Recipe MakerAI | 1/9/2026 | 1/9/2026 | The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in all versions up to, and including, 10.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (7.8) | 0.83% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 6/7/2026 | A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. The manipulation of the argument shopping_cart leads to deserialization. The… | |
| Aplazada | Media (5.3) | 0.48% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 6/7/2026 | A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image Manager. Executing a manipulation of the… | |
| Aplazada | Media (5.5) | 0.62% | — | Kirilkirkov Ecommerce Codeigniter BootstrapAI | 4/7/2026 | 6/7/2026 | A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects some unknown processing of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Multi-Image Endpoint. Performing a manipulation of the… | |
| Aplazada | Baja (2.1) | 0.49% | — | Kirilkirkov Ecommerce Codeigniter BootstrapAI | 4/7/2026 | 6/7/2026 | A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin Page. Such manipulation of the argument… | |
| Aplazada | Baja (2.1) | 0.49% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 7/7/2026 | A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. This manipulation of the argument title/description causes cross site scripting.… | |
| Aplazada | Baja (2.1) | 0.46% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 95dfa8cebbb87ab46ae450643a07241274a74dce. Affected by this issue is the function setReferrer of the file application/core/MY_Controller.php of the component Trusted Backend Interface. The manipulation of the argument href results in open… | |
| Aplazada | Alta (7.4) | 0.28% | — | Bootstrapped Visual Link PreviewAI | 25/6/2026 | 26/6/2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Bootstrapped Visual Link PreviewAI | 15/6/2026 | 17/6/2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions. | |
| Aplazada | Media (6.4) | 0.32% | — | Bootstrap ShortcodeAI | 12/5/2026 | 17/6/2026 | The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `box` shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (2.1) | 0.39% | — | Bootstrap CMSAI | 30/4/2026 | 17/6/2026 | A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulation of the argument body results in code injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Media (6.4) | 0.43% | — | Slider Bootstrap CarouselAI | 22/4/2026 | 17/6/2026 | The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and 'template' shortcode attributes in all versions up to and including 1.0.7. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The plugin uses… | |
| Aplazada | Media (6) | 0.21% | — | Bootstrapped Visual Link PreviewAI | 8/4/2026 | 24/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brecht Visual Link Preview visual-link-preview allows Server Side Request Forgery.This issue affects Visual Link Preview: from n/a through <= 2.3.0. | |
| Aplazada | Alta (8.8) | 0.27% | — | Bootstrapy CMSAI | 24/3/2026 | 17/6/2026 | Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can inject SQL payloads into the thread_id parameter of forum-thread.php, the subject parameter of contact-submit.php, the… | |
| Aplazada | Media (5.3) | 0.26% | — | Bootstrapped WP Recipe MakerAI | 27/2/2026 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This is due to the /wp-json/wp-recipe-maker/v1/integrations/instacart REST API endpoint's permission_callback being set to __return_true and a lack of subsequent authorization… | |
| Aplazada | Media (4.3) | 0.23% | — | Bootstrapped WP Recipe MakerAI | 25/2/2026 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ajax_search_recipes' and 'ajax_get_recipe' functions in all versions up to, and including, 10.2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above,… |