Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Soflyy BreakdanceAI | 6/8/2026 | 12/8/2026 | Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7. | |
| Aplazada | Alta (7.1) | 0.25% | — | BreakdanceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. | |
| Aplazada | Alta (7.2) | 0.32% | — | BreakdanceAI | 16/7/2026 | 17/7/2026 | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Analizada | Media (4.3) | 0.24% | — | Soflyy Breakdance | 1/8/2024 | 17/6/2026 | The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions. | |
| Analizada | Media (5.4) | 0.26% | — | Soflyy Breakdance | 1/8/2024 | 17/6/2026 | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (8.8) | 0.90% | — | BreakdanceAI | 14/5/2024 | 17/6/2026 | The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is due to the plugin storing custom data in metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to edit this data… | |
| Aplazada | Media (6.4) | 0.32% | — | BreakdanceAI | 6/5/2024 | 17/6/2026 | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping on user supplied post meta fields. This makes it possible for authenticated attackers with… | |
| Aplazada | Crítica (9.9) | 0.90% | — | Soflyy BreakdanceAI | 3/4/2024 | 17/6/2026 | : Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2. | |
| Modificada | Alta (8.8) | 0.30% | — | Breakdance Elegant Custom Fonts | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Louis Reingold Elegant Custom Fonts plugin <= 1.0 versions. |