Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.31% | — | Getbutterfly Modern Design Library | 26/6/2025 | 17/6/2026 | The Modern Design Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Crítica (9.1) | 1.6% | — | Openrefine Butterfly | 24/10/2024 | 17/6/2026 | The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected to be) local resource files, like images or templates. This works: "opening a connection" to these URLs opens the local file. However,… | |
| Aplazada | Alta (7.5) | 0.42% | — | Butterfly Effect Limited Monica Chatgpt AI AssistantAI | 24/10/2024 | 17/6/2026 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | |
| Aplazada | Alta (7.5) | 0.42% | — | Butterfly Effect Limited Monica Your AI CopilotAI | 24/10/2024 | 17/6/2026 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | |
| Analizada | Media (4.3) | 0.25% | — | Getbutterfly Imagepress | 12/10/2024 | 17/6/2026 | The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the 'imagepress_admin_page' function. This makes it possible for unauthenticated attackers to update plugin settings,… | |
| Analizada | Media (4.8) | 0.36% | — | Getbutterfly Imagepress | 12/10/2024 | 17/6/2026 | The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Modificada | Media (5.4) | 0.26% | — | Getbutterfly Block FOR Font Awesome | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ciprian Popescu Block for Font Awesome allows Stored XSS.This issue affects Block for Font Awesome: from n/a through 1.4.4. | |
| Modificada | Alta (8.8) | 0.26% | — | Getbutterfly Block FOR Font Awesome | 17/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu Block for Font Awesome.This issue affects Block for Font Awesome: from n/a through 1.4.0. | |
| Modificada | Media (5.4) | 0.31% | — | Getbutterfly Youtube Playlist Player | 18/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <= 4.6.7 versions. | |
| Modificada | Alta (7.5) | 0.77% | — | Butterfly-button Butterfly Button | 21/8/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFLY BUTTON (Architecture flaw) allows loss of plausible deniability and confidentiality.This issue affects BUTTERFLY BUTTON: As of 2023-08-21. | |
| Modificada | Alta (8.8) | 0.26% | — | Getbutterfly Youtube Playlist Player | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <= 4.6.4 versions. | |
| Modificada | Media (4.6) | 0.25% | — | Butterfly-button Project Butterfly-button | 15/2/2023 | 17/6/2026 | Butterfly Button plugin may leave traces of its use on user's device. Since it is used for reporting domestic problems, this may lead to spouse knowing about its use. | |
| Modificada | Crítica (9.1) | 3.7% | — | Getbutterfly Portable-phpmyadmin | 18/2/2020 | 16/6/2026 | WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities | |
| Modificada | Alta (7.5) | 2.3% | — | Butterflymedia Butterfly Organizer | 8/9/2009 | 16/6/2026 | Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter to category-delete.php with the is_js_confirmed parameter set to 1, or (2) delete arbitrary accounts via the mytable parameter to delete.php. | |
| Modificada | Media (4.3) | 1.5% | — | Butterflymedia Butterfly Organizer | 10/4/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mytable parameter to view.php, (2) mytable parameter to viewdb2.php, (3) tablehere parameter to category-rename.php, and (4) letter parameter to module-contacts.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Butterflymedia Butterfly Organizer | 27/2/2009 | 16/6/2026 | SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Butterflymedia Butterfly Organizer | 27/2/2009 | 16/6/2026 | SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name. | |
| Modificada | Media (6.8) | 1.8% | — | Butterfly | 22/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in visitor.php in Butterfly online visitors counter 1.08, when used with certain older versions of PHP with improper SERVER superglobal handling, allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter. NOTE: it could be argued… |