Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.45% | — | Getgrav Grav Plugin CommentsAI | 26/9/2026 | 28/9/2026 | The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the… | |
| Aplazada | Baja (2.7) | 0.32% | — | Comments Import ExportAI | 17/9/2026 | 18/9/2026 | The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP… | |
| Aplazada | Crítica (9.3) | 0.98% | — | Cotonti Comments PluginAI | 15/9/2026 | 16/9/2026 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget… | |
| Aplazada | Crítica (9.3) | 0.43% | — | Parallax Filament-commentsAI | 14/9/2026 | 24/9/2026 | parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies that execute in the browsers of other users viewing those comments, including… | |
| Aplazada | Alta (8.7) | 0.34% | — | Pocketmine-mpAIAdhocore Json-commentAI | 6/9/2026 | 10/9/2026 | PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash. | |
| Aplazada | Media (5.4) | 0.27% | — | Ajaxify CommentsAI | 2/9/2026 | 3/9/2026 | The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers. | |
| Aplazada | Media (5.3) | 0.26% | — | CommentsAI | 2/9/2026 | 3/9/2026 | The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowing unauthenticated users to inject SQL and read comments they are not entitled to see, including comments awaiting moderation, comments marked as spam or trashed, and comments on private and draft posts. The… | |
| Aplazada | Media (6.1) | 0.27% | — | CommentsAI | 7/8/2026 | 26/8/2026 | The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content. | |
| Aplazada | Media (5.9) | 0.24% | — | Markjaquith Subscribe TO CommentsAI | 6/8/2026 | 12/8/2026 | Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions. | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Jenkins Violation Comments TO Gitlab PluginAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Aplazada | Alta (7.6) | 0.38% | — | Cotonti CMSAICotonti CommentsAI | 5/8/2026 | 26/8/2026 | Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only sanitization) is passed to with no restriction, reachable by any member with write access to… | |
| Aplazada | Alta (7.2) | 0.51% | — | Comments WpdiscuzAI | 3/7/2026 | 6/7/2026 | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the stored comment_author_url value directly into… | |
| Analizada | Media (6.1) | 0.34% | — | Commenthol Md-fileserver | 9/6/2026 | 12/8/2026 | md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is processed and injected into the… | |
| Aplazada | Media (4.3) | 0.18% | — | Ajax Report CommentsAI | 9/6/2026 | 23/7/2026 | The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect nonce validation on the rc_options_page function. This makes it possible for unauthenticated attackers to modify plugin settings including link text… | |
| Aplazada | Media (4.3) | 0.19% | — | Remove Nofollow Commenter URLAI | 2/6/2026 | 22/7/2026 | The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify the plugin's… | |
| Aplazada | Alta (7.1) | 0.44% | — | Themeisle Disable Comments FOR ANY Post TypesAI | 27/5/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types (Remove comments) comments-plus allows Password Recovery Exploitation.This issue affects Disable Comments for Any Post Types (Remove comments): from n/a through <= 1.3.0. | |
| Aplazada | Media (5.8) | 0.34% | — | Decent CommentsAI | 20/5/2026 | 24/7/2026 | The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses. | |
| Aplazada | Media (6.1) | 0.36% | — | LJ Comments Import ReloadedAI | 20/5/2026 | 23/7/2026 | The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Comment SystemAI | 8/5/2026 | 17/6/2026 | A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_comment.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Aplazada | Media (6.5) | 0.39% | — | Subscribe TO Comments ReloadedAI | 5/5/2026 | 17/6/2026 | The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm in all versions up to, and including, 240119. This makes it possible for unauthenticated attackers to extract the global key from any… | |
| Aplazada | Media (4.4) | 0.30% | — | Buzz CommentsAI | 22/4/2026 | 17/6/2026 | The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_comments_avatar_image) setting in all versions up to, and including, 0.9.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.23% | — | DX Unanswered CommentsAI | 22/4/2026 | 17/6/2026 | The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation on the plugin's settings form in the dxuc-unanswered-comments-admin-page.php file. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.4) | 0.39% | — | Short Comment FilterAI | 22/4/2026 | 17/6/2026 | The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Minimum Count' settings field in all versions up to and including 2.2. This is due to insufficient input sanitization (no sanitize callback on register_setting) and missing output escaping (no esc_attr() on the echoed… | |
| Aplazada | Crítica (9.3) | 0.46% | — | DBTAIPeter Evans Find CommentAI | 7/4/2026 | 24/7/2026 | dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Inside the reusable workflow dbt-labs/actions/blob/main/.github/workflows/open-issue-in-repo.yml, the prep job uses peter-evans/find-comment to search for an existing comment… | |
| Aplazada | Alta (7.7) | 0.39% | — | Webtoffee Comments Import AND Export WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comments Import & Export: from n/a through <= 2.4.9. |