Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.51%—Complianz Gdpr Ccpa Cookie Consent BannerAI18/9/202618/9/2026
The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (5.3)0.33%—Really-simple-plugins ComplianzAI23/7/202612/8/2026
Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
AplazadaAlta (7.2)0.54%—Really-simple-plugins ComplianzAI23/7/202623/7/2026
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
AplazadaMedia (4.4)0.21%—Really-simple-plugins ComplianzAI23/7/202623/7/2026
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
AplazadaMedia (5.3)0.44%—Really-simple-plugins ComplianzAI29/4/202617/6/2026
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/complianz/v1/consent-area/{post_id}/{block_id} using __return_true as the permission_callback, allowing any…
AplazadaMedia (4.9)0.22%—Complianz Gdpr Ccpa Cookie ConsentAI26/3/202617/6/2026
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.4.2. This is due to the `revert_divs_to_summary` function replacing `&#8221;` HTML entities with literal double-quote characters (`"`) in post content without subsequent…
AplazadaMedia (6.4)0.26%—Really-simple-plugins ComplianzAI18/2/202617/6/2026
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cmplz-accept-link shortcode in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaMedia (4.3)0.20%—Really-simple-plugins Complianz2/3/202417/6/2026
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD.php. This makes it possible for unauthenticated attackers to delete…
ModificadaMedia (4.8)0.32%—Really-simple-plugins Complianz4/1/202417/6/2026
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…
ModificadaAlta (8.8)0.34%—Really-simple-plugins Complianz30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request Forgery.This issue affects Complianz: from n/a through 6.4.5; Complianz Premium: from n/a through 6.4.7.
ModificadaAlta (8.8)0.31%—Really-simple-plugins Complianz30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripting (XSS).This issue affects Complianz: from n/a through 6.4.4; Complianz Premium: from n/a through 6.4.6.1.
ModificadaMedia (5.4)0.56%—Really-simple-plugins Complianz27/3/202317/6/2026
The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site…
ModificadaAlta (8.8)1.3%—Really-simple-plugins Complianz7/11/202217/6/2026
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco…
ModificadaMedia (6.1)0.88%—Really-simple-plugins Complianz14/2/202217/6/2026
The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting