Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.37% | — | Wpclever WPC Admin ColumnsAI | 12/8/2026 | 26/8/2026 | The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators. | |
| Aplazada | Media (5.4) | 0.23% | — | Admin Columns FOR ACF FieldsAI | 1/8/2026 | 26/8/2026 | The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users… | |
| Aplazada | Alta (8.8) | 1.2% | — | Admincolumns Admin ColumnsAI | 5/6/2026 | 23/7/2026 | The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the `IdsToCollection::get_ids_from_string()` function, which processes… | |
| Aplazada | Media (6.4) | 0.41% | — | Bestwebsoft ColumnsAI | 8/4/2026 | 24/7/2026 | The Columns by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the [print_clmns] shortcode in all versions up to and including 1.0.3. This is due to insufficient input sanitization and output escaping on the 'id' attribute. The shortcode receives the… | |
| Aplazada | Media (6.4) | 0.21% | — | CM CSS ColumnsAI | 24/1/2026 | 17/6/2026 | The CM CSS Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' shortcode attribute in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.18% | — | Precise ColumnsAI | 11/11/2025 | 17/6/2026 | The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attribute in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input or escaping output when inserting the wrapper ID into the generated HTML. This makes it… | |
| Aplazada | Alta (8.8) | 0.40% | — | Wpclever WPC Admin ColumnsAI | 12/4/2025 | 17/6/2026 | The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due to the plugin not properly restricting user meta values that can be updated through the ajax_edit_save() function. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (6.5) | 0.28% | — | Tormorten Foundation ColumnsAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tormorten Foundation Columns foundation-columns allows Stored XSS.This issue affects Foundation Columns: from n/a through <= 0.8. | |
| Aplazada | Media (4.3) | 0.23% | — | Deepak Khokhar Manage User ColumnsAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Deepak Khokhar Manage User Columns manage-user-columns allows Cross Site Request Forgery.This issue affects Manage User Columns: from n/a through <= 1.0.5. | |
| Aplazada | Media (6.5) | 0.31% | — | WEN Themes WEN Responsive ColumnsAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Responsive Columns allows Stored XSS.This issue affects WEN Responsive Columns: from n/a through 1.3.2. | |
| Modificada | Media (5.4) | 0.38% | — | Bamboo MCR Bamboo Columns | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bamboo Mcr Bamboo Columns allows Stored XSS.This issue affects Bamboo Columns: from n/a through 1.6.1. | |
| Modificada | Media (5.4) | 0.42% | — | Bamboo MCR Bamboo Columns | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bamboo Mcr Bamboo Columns plugin <= 1.6.1 versions. | |
| Modificada | Media (5.4) | 0.43% | — | WP Post Columns Project WP Post Columns | 22/11/2023 | 17/6/2026 | The WP Post Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'column' shortcode in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5.4) | 0.47% | — | Genesis Columns Advanced Project Genesis Columns Advanced | 23/1/2023 | 17/6/2026 | The Genesis Columns Advanced WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks which could be used against high-privilege users… | |
| Modificada | Media (4.8) | 0.60% | — | Advanced WP Columns Project Advanced WP Columns | 5/12/2022 | 17/6/2026 | The Advanced WP Columns WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.4) | 0.93% | — | Admincolumns Admin Columns | 12/7/2021 | 17/6/2026 | The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was no escaping applied to the contents of "Custom Field" columns. | |
| Modificada | Media (5.4) | 1.00% | — | Admincolumns Admin Columns | 21/6/2021 | 17/6/2026 | The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in… | |
| Modificada | Media (5.4) | 72% | — | Jenkins Extra Columns | 30/3/2021 | 17/6/2026 | Jenkins Extra Columns Plugin 1.22 and earlier does not escape parameter values in the build parameters column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Compact Columns | 3/6/2020 | 17/6/2026 | Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a stored cross-site scripting vulnerability that can be exploited by users with Job/Configure permission. | |
| Modificada | Alta (8.8) | 2.4% | — | Admincolumns Admin Columns | 8/11/2019 | 17/6/2026 | A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious code. Other users might download this… | |
| Modificada | Media (5.4) | 1.2% | — | Jenkins Extra Columns | 9/2/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter. |