Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.17% | — | Broken Link ManagerAI | 24/11/2025 | 17/6/2026 | The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.2) | 1.6% | — | Broken Link Manager Project Broken Link Manager | 23/8/2021 | 17/6/2026 | The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an authenticated SQL injection issue | |
| Modificada | Media (6.1) | 0.98% | — | K-78 Broken Link Manager | 10/10/2019 | 17/6/2026 | The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action. | |
| Modificada | Crítica (9.8) | 2.4% | — | K-78 Broken Link Manager | 10/10/2019 | 17/6/2026 | The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter. | |
| Modificada | Media (6.1) | 1.5% | — | K-78 Broken Link Manager | 7/10/2019 | 17/6/2026 | The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist. |