Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.45% | — | Getgrav Grav Plugin CommentsAI | 26/9/2026 | 28/9/2026 | The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the… | |
| Aplazada | Baja (2.7) | 0.32% | — | Comments Import ExportAI | 17/9/2026 | 18/9/2026 | The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP… | |
| Aplazada | Crítica (9.3) | 0.98% | — | Cotonti Comments PluginAI | 15/9/2026 | 16/9/2026 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget… | |
| Aplazada | Crítica (9.3) | 0.43% | — | Parallax Filament-commentsAI | 14/9/2026 | 24/9/2026 | parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies that execute in the browsers of other users viewing those comments, including… | |
| Aplazada | Media (5.4) | 0.27% | — | Ajaxify CommentsAI | 2/9/2026 | 3/9/2026 | The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers. | |
| Aplazada | Media (5.3) | 0.26% | — | CommentsAI | 2/9/2026 | 3/9/2026 | The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowing unauthenticated users to inject SQL and read comments they are not entitled to see, including comments awaiting moderation, comments marked as spam or trashed, and comments on private and draft posts. The… | |
| Aplazada | Media (6.1) | 0.27% | — | CommentsAI | 7/8/2026 | 26/8/2026 | The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content. | |
| Aplazada | Media (5.9) | 0.24% | — | Markjaquith Subscribe TO CommentsAI | 6/8/2026 | 12/8/2026 | Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions. | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Jenkins Violation Comments TO Gitlab PluginAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Aplazada | Alta (7.6) | 0.38% | — | Cotonti CMSAICotonti CommentsAI | 5/8/2026 | 26/8/2026 | Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only sanitization) is passed to with no restriction, reachable by any member with write access to… | |
| Aplazada | Alta (7.2) | 0.51% | — | Comments WpdiscuzAI | 3/7/2026 | 6/7/2026 | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the stored comment_author_url value directly into… | |
| Aplazada | Media (4.3) | 0.18% | — | Ajax Report CommentsAI | 9/6/2026 | 23/7/2026 | The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect nonce validation on the rc_options_page function. This makes it possible for unauthenticated attackers to modify plugin settings including link text… | |
| Aplazada | Alta (7.1) | 0.44% | — | Themeisle Disable Comments FOR ANY Post TypesAI | 27/5/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types (Remove comments) comments-plus allows Password Recovery Exploitation.This issue affects Disable Comments for Any Post Types (Remove comments): from n/a through <= 1.3.0. | |
| Aplazada | Media (5.8) | 0.34% | — | Decent CommentsAI | 20/5/2026 | 24/7/2026 | The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses. | |
| Aplazada | Media (6.1) | 0.36% | — | LJ Comments Import ReloadedAI | 20/5/2026 | 23/7/2026 | The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (6.5) | 0.39% | — | Subscribe TO Comments ReloadedAI | 5/5/2026 | 17/6/2026 | The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm in all versions up to, and including, 240119. This makes it possible for unauthenticated attackers to extract the global key from any… | |
| Aplazada | Media (4.4) | 0.30% | — | Buzz CommentsAI | 22/4/2026 | 17/6/2026 | The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_comments_avatar_image) setting in all versions up to, and including, 0.9.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.23% | — | DX Unanswered CommentsAI | 22/4/2026 | 17/6/2026 | The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation on the plugin's settings form in the dxuc-unanswered-comments-admin-page.php file. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.7) | 0.39% | — | Webtoffee Comments Import AND Export WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comments Import & Export: from n/a through <= 2.4.9. | |
| Aplazada | Media (4.3) | 0.12% | — | Stopwords FOR CommentsAI | 14/1/2026 | 17/6/2026 | The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing nonce validation on the 'set_stopwords_for_comments' and 'delete_stopwords_for_comments' functions. This makes it possible for unauthenticated attackers to add… | |
| Aplazada | Media (4.3) | 0.18% | — | Quote CommentsAI | 7/1/2026 | 17/6/2026 | The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.0. This is due to missing authorization checks in the quotecomments_add_admin function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update… | |
| Aplazada | Media (5.3) | 0.26% | — | CommentsAI | 1/1/2026 | 17/6/2026 | The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet. | |
| Aplazada | Media (5.9) | 0.18% | — | Alex Moss Google-plus-commentsAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Moss Google+ Comments google-plus-comments allows Stored XSS.This issue affects Google+ Comments: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.24% | — | Digitalzoomstudio Comments Capcha BOXAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Comments Capcha Box comments-capcha-box allows Reflected XSS.This issue affects Comments Capcha Box: from n/a through <= 1.1. | |
| Aplazada | Media (6.4) | 0.25% | — | Surbma Recent Comments ShortcodeAI | 16/8/2025 | 17/6/2026 | The Surbma | Recent Comments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'recent-comments' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |