Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.45% | — | Plugin-devs Post Carousel Slider FOR ElementorAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Plugin Devs Post Carousel Slider for Elementor post-carousel-slider-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Carousel Slider for Elementor: from n/a through <= 1.7.0. | |
| Aplazada | Baja (3.5) | 0.25% | — | Plugin-devs Ecommerce-product-carousel-slider-for-elementorAI | 5/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Plugin Devs Product Carousel Slider for Elementor ecommerce-product-carousel-slider-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Carousel Slider for Elementor: from n/a through <= 2.1.3. | |
| Analizada | Alta (8.8) | 3.1% | — | I13websolution Thumbnail Carousel Slider | 25/7/2025 | 17/6/2026 | The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions up to 1.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected… | |
| Analizada | Media (4.3) | 0.29% | — | Plugin-devs Post Carousel Slider FOR Elementor | 26/6/2025 | 17/6/2026 | The Post Carousel Slider for Elementor plugin for WordPress is vulnerable to improper authorization due to a missing capability check on the process_wbelps_promo_form() function in all versions up to, and including, 1.6.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (6.5) | 0.35% | — | Wpwax Logo Carousel SliderAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Logo Carousel Slider logo-carousel-slider allows Stored XSS.This issue affects Logo Carousel Slider: from n/a through <= 2.1.3. | |
| Analizada | Media (4.9) | 0.44% | — | I13websolution Thumbnail Carousel Slider | 15/3/2025 | 17/6/2026 | The Thumbnail carousel slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Analizada | Media (4.7) | 0.84% | — | Wp-buy OWL Carousel Slider | 17/2/2025 | 17/6/2026 | The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.1) | 0.13% | — | Bhaskardhote Post Carousel SliderAI | 31/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Post Carousel Slider post-carousel-slider allows Stored XSS.This issue affects Post Carousel Slider: from n/a through <= 2.0.1. | |
| Aplazada | Media (5.9) | 0.35% | — | Wpwax Product Carousel Slider AND Grid Ultimate FOR WoocommerceAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce woo-product-carousel-slider-and-grid-ultimate allows Stored XSS.This issue affects Product Carousel Slider & Grid Ultimate for WooCommerce: from n/a… | |
| Aplazada | Media (6.4) | 0.38% | — | Post Carousel SliderAI | 14/12/2024 | 17/6/2026 | The Post Carousel & Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-cs' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.3) | 0.56% | — | Majeedraza Carousel Slider | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carousel Slider: from n/a through 2.2.2. | |
| Aplazada | Alta (8.8) | 0.82% | — | Wpclever WPC Product Carousel SliderAI | 12/12/2024 | 17/6/2026 | The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.10 via the 'theme' attribute of the `wcpcsu` shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (6.4) | 0.43% | — | Depicter Slider AND Carousel SliderAI | 6/12/2024 | 17/6/2026 | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘addExtraMimeType’ function in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level… | |
| Aplazada | Media (6.5) | 0.24% | — | Plugin-devs Post Carousel Slider FOR ElementorAI | 1/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Devs Post Carousel Slider for Elementor post-carousel-slider-for-elementor allows Stored XSS.This issue affects Post Carousel Slider for Elementor: from n/a through <= 1.5.0. | |
| Aplazada | Media (6.5) | 0.50% | — | Wpwax Product Carousel Slider AND Grid UltimateAI | 23/9/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce woo-product-carousel-slider-and-grid-ultimate.This issue affects Product Carousel Slider & Grid Ultimate for WooCommerce: from n/a… | |
| Analizada | Media (4.8) | 0.34% | — | Majeedraza Carousel Slider | 13/9/2024 | 17/6/2026 | The Carousel Slider WordPress plugin before 2.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Alta (7.2) | 0.50% | — | I13websolution Video Carousel Slider With Lightbox | 11/9/2024 | 17/6/2026 | The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Media (4.3) | 0.23% | — | Majeedraza Carousel Slider | 2/9/2024 | 17/6/2026 | WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site. | |
| Modificada | Media (4.3) | 0.27% | — | Majeedraza Carousel Slider | 2/9/2024 | 17/6/2026 | WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site. | |
| Aplazada | Alta (8.8) | 1.0% | — | Slider AND Carousel Slider BY DepicterAI | 14/8/2024 | 17/6/2026 | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary… | |
| Analizada | Media (5.4) | 0.40% | — | Majeedraza Carousel Slider | 21/5/2024 | 17/6/2026 | The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks | |
| Analizada | Media (4.7) | 0.50% | — | Majeedraza Carousel Slider | 3/5/2024 | 17/6/2026 | The Carousel Slider WordPress plugin before 2.2.10 does not validate and escape some of its Slide options before outputting them back in the page/post where the related Slide shortcode is embed, which could allow users with the Editor role and above to perform Stored Cross-Site Scripting attacks | |
| Analizada | Media (4.7) | 0.48% | — | Majeedraza Carousel Slider | 15/4/2024 | 17/6/2026 | The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 1.2% | — | Wpwax Product Carousel Slider & Grid Ultimate FOR Woocommerce | 13/3/2024 | 17/6/2026 | The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted input via shortcode. This makes it possible for authenticated attackers, with contributor access and above, to inject a PHP… | |
| Modificada | Media (6.1) | 0.39% | — | Aazztech Woocommerce Product Carousel Slider | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AazzTech WooCommerce Product Carousel Slider plugin <= 3.3.5 versions. |