Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.17% | — | Advanced Classifieds Directory PROAI | 10/8/2026 | 26/8/2026 | The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX action `acadp_public_custom_fields_listings`. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Strategy11 AWP ClassifiedsAI | 27/7/2026 | 27/7/2026 | Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | AWP ClassifiedsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions. | |
| Aplazada | Crítica (10) | 0.45% | — | Dj-extensions Dj-classifiedsAI | 20/7/2026 | 23/7/2026 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE. | |
| Analizada | Alta (8.8) | 0.49% | — | Cmsjunkie Classifiedsmanager | 19/6/2026 | 19/8/2026 | Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch, adType, and citySearch parameters to the… | |
| Aplazada | Alta (7.5) | 0.43% | — | AWP ClassifiedsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Strategy11 Another Wordpress Classifieds PluginAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= 4.4.5. | |
| Aplazada | Alta (7.5) | 0.69% | — | Strategy11 AWP ClassifiedsAI | 5/5/2026 | 17/6/2026 | The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.24% | — | Silurus Classifieds ScriptAI | 6/3/2026 | 17/6/2026 | Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ID parameter. Attackers can send GET requests to wcategory.php with crafted SQL payloads in the ID parameter to extract database table… | |
| Aplazada | Media (5.3) | 0.34% | — | Strategy11 AWP ClassifiedsAI | 23/1/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Retrieve Embedded Sensitive Data.This issue affects AWP Classifieds: from n/a through <= 4.4.3. | |
| Aplazada | Media (4.3) | 0.13% | — | Pluginsware Advanced Classifieds AND Directory PROAI | 24/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in pluginsware Advanced Classifieds & Directory Pro advanced-classifieds-and-directory-pro allows Cross Site Request Forgery.This issue affects Advanced Classifieds & Directory Pro: from n/a through <= 3.2.9. | |
| Aplazada | Media (5.3) | 0.32% | — | Strategy11 Another Wordpress Classifieds PluginAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Code Injection.This issue affects AWP Classifieds: from n/a through <= 4.4.3. | |
| Aplazada | Alta (8.5) | 0.32% | — | Dj-classifiedsAIJoomlaAI | 15/8/2025 | 17/6/2026 | A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands. | |
| Analizada | Media (4.3) | 0.31% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 8/4/2025 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all versions up to, and including, 1.4.66. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.22% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 8/4/2025 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.8) | 0.90% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 8/4/2025 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.3) | 0.30% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 22/3/2025 | 17/6/2026 | The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.26% | — | Themeglow Cleanup - Directory Listing AND ClassifiedsAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeglow Cleanup – Directory Listing & Classifieds WordPress Plugin cleanup-light allows Reflected XSS.This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through <= 1.0.4. | |
| Analizada | Media (5.4) | 0.33% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 16/1/2025 | 17/6/2026 | The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it… | |
| Aplazada | Alta (8.5) | 0.51% | — | Pluginsware Advanced Classifieds AND Directory PROAI | 9/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginsWare Advanced Classifieds & Directory Pro allows Path Traversal.This issue affects Advanced Classifieds & Directory Pro: from n/a through 3.1.3. | |
| Modificada | Media (5.3) | 0.33% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 2/7/2024 | 17/6/2026 | The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to unpublish arbitrary… | |
| Modificada | Alta (8.8) | 0.32% | — | Strategy11 AWP Classifieds | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Strategy11 AWP ClassifiedsAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1. | |
| Aplazada | Media (4.3) | 0.54% | — | Advanced Classifieds Directory PROAI | 9/4/2024 | 17/6/2026 | The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_callback_delete_attachment function in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber access or higher,… | |
| Aplazada | Alta (8.8) | 0.26% | — | Pixelemu TerraclassifiedsAI | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelemu TerraClassifieds.This issue affects TerraClassifieds: from n/a through 2.0.3. |