Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.23% | — | Wptasty Business DirectoryAI | 30/9/2026 | 30/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27. | |
| Aplazada | Media (5.4) | 0.21% | — | Business DirectoryAI | 30/9/2026 | 30/9/2026 | Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Connections-pro Connections Business DirectoryAI | 30/9/2026 | 30/9/2026 | The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including… | |
| Aplazada | Media (6.5) | 0.27% | — | Business DirectoryAI | 3/9/2026 | 7/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Business DirectoryAI | 3/9/2026 | 5/9/2026 | Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | |
| Aplazada | Alta (8.7) | 0.43% | — | Cmsjunkie J-business DirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limitstart[]) could trigger PHP type errors in arithmetic, and limit was not validated before use in list queries. | |
| Aplazada | Media (4.6) | 0.21% | — | Cmsjunkie J-business DirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install, demo-data wipe, cache/statistics archive,… | |
| Aplazada | Media (6.9) | 0.41% | — | Cmsjunkie J-business DirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 | |
| Aplazada | Alta (7.1) | 0.25% | — | Business DirectoryAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Business DirectoryAI | 6/8/2026 | 12/8/2026 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Quantumcloud Simple Business Directory PROAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4. | |
| Aplazada | Media (6.4) | 0.35% | — | CM Business DirectoryAI | 3/7/2026 | 6/7/2026 | The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.33% | — | Business DirectoryAI | 29/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Business DirectoryAI | 29/6/2026 | 29/6/2026 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. | |
| Aplazada | Media (6.1) | 0.25% | — | Business DirectoryAI | 29/6/2026 | 29/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. | |
| Aplazada | Alta (8.8) | 0.30% | — | Netartmedia PHP Business DirectoryAI | 12/3/2026 | 17/6/2026 | Netartmedia PHP Business Directory 4.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to the loginaction.php endpoint with crafted SQL payloads in the Email field to extract… | |
| Aplazada | Media (5.9) | 0.24% | — | Creativemindssolutions CM Business DirectoryAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Business Directory cm-business-directory allows Stored XSS.This issue affects CM Business Directory: from n/a through <= 1.5.3. | |
| Aplazada | Media (5.3) | 0.33% | — | Businessdirectoryplugin Business Directory PluginAI | 18/2/2026 | 17/6/2026 | The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check in all versions up to, and including, 6.4.20. This makes it possible for unauthenticated attackers to modify arbitrary listings, including changing titles, content, and email addresses, by directly… | |
| Aplazada | Alta (7.5) | 0.53% | — | Businessdirectoryplugin Business Directory PluginAI | 18/2/2026 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'payment' parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Media (4.9) | 0.34% | — | Strategy11 Business DirectoryAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.19. | |
| Aplazada | Media (4.3) | 0.12% | — | Strategy11 Business DirectoryAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Cross Site Request Forgery.This issue affects Business Directory: from n/a through <= 6.4.19. | |
| Aplazada | Media (5.3) | 0.27% | — | Chamber Dashboard Business DirectoryAI | 25/11/2025 | 17/6/2026 | The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing capability check on the cdash_watch_for_export() function in all versions up to, and including, 3.3.11. This makes it possible for unauthenticated attackers to export business directory information,… | |
| Aplazada | Media (4.3) | 0.19% | — | Strategy11 Business DirectoryAI | 29/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.18. | |
| Aplazada | Media (6.4) | 0.24% | — | CM Business DirectoryAI | 26/9/2025 | 17/6/2026 | The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featured_image' shortcode in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 0.37% | — | Quantumcloud Simple Business Directory PROAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9. |