Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

378 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.24%—Easy Paypal Stripe BUY NOW ButtonAI2/10/20262/10/2026
The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.
AplazadaMedia (6.1)0.29%—Social Media Share Buttons Social Sharing IconsAI1/10/20261/10/2026
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaAlta (8.6)0.26%—PRO Like ButtonAI1/10/20261/10/2026
The Pro Like Button WordPress plugin before 2.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
AplazadaAlta (7.1)0.19%—Razorpay Payment ButtonAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions.
AplazadaMedia (6.4)0.20%—Social Chat Click TO Chat APP ButtonAI5/9/20268/9/2026
The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaAlta (7.1)0.18%—Social Media Share Buttons Social Sharing IconsAI2/9/20263/9/2026
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button.…
AplazadaMedia (6.8)0.29%—Social Media Share Buttons Social Sharing IconsAI2/9/20263/9/2026
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts…
AplazadaAlta (8.5)0.36%—Likebtn Like Button RatingAI27/8/202628/8/2026
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
AplazadaCrítica (9.8)0.63%—Soclever Social Login Sharing Buttons With AnalyticsAI22/8/202626/8/2026
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators.…
AplazadaMedia (5.4)0.29%—BigbluebuttonAI20/8/202616/9/2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged user could store a crafted meeting name that embedded script content, and the…
AplazadaMedia (4.9)0.31%—BigbluebuttonAI20/8/202616/9/2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. akka-bbb-apps/src/main/scala/org/bigbluebutton/core/apps/presentationpod/RemovePresentationPubMsgHdlr.scala did…
AplazadaAlta (8.5)0.58%—BigbluebuttonAI20/8/202616/9/2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutRoomUserDAO.scala. The method…
AplazadaAlta (7.1)0.37%—BigbluebuttonAI20/8/202616/9/2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an existingUserID for an active participant could reuse…
AplazadaAlta (7.1)0.25%—Meril Blog Floating ButtonAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
AplazadaMedia (5.3)0.32%—Payment Button FOR PaypalAI12/8/202626/8/2026
The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.
AplazadaMedia (4.1)0.29%—BigbluebuttonAITHM PilosAI6/8/202610/9/2026
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that opens a new browsing context (e.g., target="_blank") retain a window.opener reference back to the…
AplazadaAlta (7.1)0.25%—Wpplugin Easy Paypal BUY NOW ButtonAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
AplazadaMedia (6.1)0.27%—Meril Blog Floating ButtonAI3/8/202626/8/2026
The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. This allows an unauthenticated attacker to store a malicious script that…
AplazadaMedia (6.5)0.41%—Improved Save ButtonAI30/7/202630/7/2026
The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action in all versions up to, and including, 1.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
AplazadaMedia (6.8)0.43%—BigbluebuttonAI16/7/202617/7/2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The redirect following logic now pins resolved IPs. This issue is fixed in version 3.0.23.
AplazadaAlta (8.1)0.48%—BigbluebuttonAI16/7/202617/7/2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java and ValidationService.java, allowing a user to send valid requests to some endpoints without a…
AplazadaAlta (8.1)0.46%—BigbluebuttonAI16/7/202617/7/2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java and bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy,…
AplazadaMedia (6.1)0.37%—MaxbuttonsAI27/6/202629/6/2026
The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, and including, 9.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (5.4)0.29%—Designsandcode Forget About Shortcode ButtonsAI26/6/202629/9/2026
Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
AplazadaAlta (7.4)0.28%—Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI15/6/202617/6/2026
Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp; Chat Buttons <= 1.4.8 versions.