Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Automotive CAR Dealership BusinessAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions.
AplazadaMedia (6.4)0.16%—Automotive CAR Dealership BusinessAI29/5/202621/7/2026
The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom field in Portfolio Items in all versions up to, and including, 13.4.1. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the…
AplazadaAlta (7.1)0.18%—Thememakers CAR DealerAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeMakers Car Dealer cardealer allows Reflected XSS.This issue affects Car Dealer: from n/a through <= 1.6.7.
AplazadaAlta (8.8)0.25%—Netartmedia PHP CAR DealerAI12/3/202617/6/2026
Netartmedia PHP Car Dealer contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can submit POST requests to index.php with crafted SQL payloads in the features[] parameter to extract…
AplazadaMedia (6.4)0.27%—Automotive CAR Dealership BusinessAI27/2/202617/6/2026
The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Call to Action' custom fields in all versions up to, and including, 13.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the 'action_text',…
AplazadaCrítica (9.8)0.59%—Thememakers CAR DealerAI23/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer cardealer allows Object Injection.This issue affects Car Dealer: from n/a through < 1.6.8.
AnalizadaMedia (4.3)0.31%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing8/4/202517/6/2026
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all versions up to, and including, 1.4.66. This makes it possible for authenticated attackers, with…
AnalizadaMedia (5.4)0.22%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing8/4/202517/6/2026
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.8)0.90%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing8/4/202517/6/2026
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with…
AnalizadaMedia (4.3)0.30%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing22/3/202517/6/2026
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. This makes it possible for authenticated attackers,…
AnalizadaAlta (8.8)1.1%—Thememakers CAR Dealer Automotive27/2/202517/6/2026
The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_post_photo() and add_car() functions in all versions up to, and including, 1.6.3. This makes it possible for authenticated attackers, with…
AnalizadaMedia (5.4)0.33%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing16/1/202517/6/2026
The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…
AplazadaMedia (4.3)0.44%—Sminozzi CAR DealerAI13/12/202417/6/2026
Missing Authorization vulnerability in sminozzi Car Dealer cardealer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Dealer: from n/a through <= 4.46.
ModificadaMedia (5.3)0.33%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing2/7/202417/6/2026
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to unpublish arbitrary…
AplazadaBaja (2.7)0.37%—Billminozzi CAR DealerAI17/5/202417/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a through 4.15.
ModificadaAlta (7.5)0.51%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing13/11/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6.
ModificadaMedia (6.1)0.33%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing27/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.
ModificadaAlta (8.8)0.25%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions.
ModificadaAlta (8.8)1.1%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing12/12/202217/6/2026
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
ModificadaMedia (6.5)0.34%—CAR Dealer Project CAR Dealer12/12/202217/6/2026
The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org
ModificadaMedia (6.1)1.4%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing24/2/202017/6/2026
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.
ModificadaMedia (6.5)1.2%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing24/2/202017/6/2026
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.
ModificadaAlta (7.5)3.1%—CAR Dealer / Auto Dealer Responsive Project CAR Dealer / Auto Dealer Responsive11/10/201917/6/2026
The ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.