Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

127 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.45%—Getgrav Grav Plugin CommentsAI26/9/202628/9/2026
The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the…
AplazadaBaja (2.7)0.32%—Comments Import ExportAI17/9/202618/9/2026
The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP…
AplazadaCrítica (9.3)0.98%—Cotonti Comments PluginAI15/9/202616/9/2026
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget…
AplazadaCrítica (9.3)0.43%—Parallax Filament-commentsAI14/9/202624/9/2026
parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies that execute in the browsers of other users viewing those comments, including…
AplazadaMedia (5.4)0.27%—Ajaxify CommentsAI2/9/20263/9/2026
The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.
AplazadaMedia (5.3)0.26%—CommentsAI2/9/20263/9/2026
The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowing unauthenticated users to inject SQL and read comments they are not entitled to see, including comments awaiting moderation, comments marked as spam or trashed, and comments on private and draft posts. The…
AplazadaMedia (6.1)0.27%—CommentsAI7/8/202626/8/2026
The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content.
AplazadaMedia (5.9)0.24%—Markjaquith Subscribe TO CommentsAI6/8/202612/8/2026
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
Pendiente de análisisMedia (4.3)0.29%—Jenkins Violation Comments TO Gitlab PluginAI5/8/202631/8/2026
A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
AplazadaAlta (7.6)0.38%—Cotonti CMSAICotonti CommentsAI5/8/202626/8/2026
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only sanitization) is passed to with no restriction, reachable by any member with write access to…
AplazadaAlta (7.2)0.51%—Comments WpdiscuzAI3/7/20266/7/2026
The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the stored comment_author_url value directly into…
AplazadaMedia (4.3)0.18%—Ajax Report CommentsAI9/6/202623/7/2026
The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect nonce validation on the rc_options_page function. This makes it possible for unauthenticated attackers to modify plugin settings including link text…
AplazadaAlta (7.1)0.44%—Themeisle Disable Comments FOR ANY Post TypesAI27/5/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types (Remove comments) comments-plus allows Password Recovery Exploitation.This issue affects Disable Comments for Any Post Types (Remove comments): from n/a through <= 1.3.0.
AplazadaMedia (5.8)0.34%—Decent CommentsAI20/5/202624/7/2026
The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.
AplazadaMedia (6.1)0.36%—LJ Comments Import ReloadedAI20/5/202623/7/2026
The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (6.5)0.39%—Subscribe TO Comments ReloadedAI5/5/202617/6/2026
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm in all versions up to, and including, 240119. This makes it possible for unauthenticated attackers to extract the global key from any…
AplazadaMedia (4.4)0.30%—Buzz CommentsAI22/4/202617/6/2026
The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_comments_avatar_image) setting in all versions up to, and including, 0.9.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.23%—DX Unanswered CommentsAI22/4/202617/6/2026
The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation on the plugin's settings form in the dxuc-unanswered-comments-admin-page.php file. This makes it possible for unauthenticated attackers to…
AplazadaAlta (7.7)0.39%—Webtoffee Comments Import AND Export WoocommerceAI25/3/202617/6/2026
Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comments Import & Export: from n/a through <= 2.4.9.
AplazadaMedia (4.3)0.12%—Stopwords FOR CommentsAI14/1/202617/6/2026
The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing nonce validation on the 'set_stopwords_for_comments' and 'delete_stopwords_for_comments' functions. This makes it possible for unauthenticated attackers to add…
AplazadaMedia (4.3)0.18%—Quote CommentsAI7/1/202617/6/2026
The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.0. This is due to missing authorization checks in the quotecomments_add_admin function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update…
AplazadaMedia (5.3)0.26%—CommentsAI1/1/202617/6/2026
The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.
AplazadaMedia (5.9)0.18%—Alex Moss Google-plus-commentsAI26/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Moss Google+ Comments google-plus-comments allows Stored XSS.This issue affects Google+ Comments: from n/a through <= 1.0.
AplazadaAlta (7.1)0.24%—Digitalzoomstudio Comments Capcha BOXAI20/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Comments Capcha Box comments-capcha-box allows Reflected XSS.This issue affects Comments Capcha Box: from n/a through <= 1.1.
AplazadaMedia (6.4)0.25%—Surbma Recent Comments ShortcodeAI16/8/202517/6/2026
The Surbma | Recent Comments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'recent-comments' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…