Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.51% | — | Complianz Gdpr Ccpa Cookie Consent BannerAI | 18/9/2026 | 18/9/2026 | The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.33% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 23/7/2026 | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | |
| Aplazada | Media (4.4) | 0.21% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 23/7/2026 | Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. | |
| Aplazada | Media (5.3) | 0.44% | — | Really-simple-plugins ComplianzAI | 29/4/2026 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/complianz/v1/consent-area/{post_id}/{block_id} using __return_true as the permission_callback, allowing any… | |
| Aplazada | Media (4.9) | 0.22% | — | Complianz Gdpr Ccpa Cookie ConsentAI | 26/3/2026 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.4.2. This is due to the `revert_divs_to_summary` function replacing `”` HTML entities with literal double-quote characters (`"`) in post content without subsequent… | |
| Aplazada | Media (6.4) | 0.26% | — | Really-simple-plugins ComplianzAI | 18/2/2026 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cmplz-accept-link shortcode in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (4.3) | 0.20% | — | Really-simple-plugins Complianz | 2/3/2024 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD.php. This makes it possible for unauthenticated attackers to delete… | |
| Modificada | Media (4.8) | 0.32% | — | Really-simple-plugins Complianz | 4/1/2024 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions… | |
| Modificada | Alta (8.8) | 0.34% | — | Really-simple-plugins Complianz | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request Forgery.This issue affects Complianz: from n/a through 6.4.5; Complianz Premium: from n/a through 6.4.7. | |
| Modificada | Alta (8.8) | 0.31% | — | Really-simple-plugins Complianz | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripting (XSS).This issue affects Complianz: from n/a through 6.4.4; Complianz Premium: from n/a through 6.4.6.1. | |
| Modificada | Media (5.4) | 0.56% | — | Really-simple-plugins Complianz | 27/3/2023 | 17/6/2026 | The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site… | |
| Modificada | Alta (8.8) | 1.3% | — | Really-simple-plugins Complianz | 7/11/2022 | 17/6/2026 | The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco… | |
| Modificada | Media (6.1) | 0.88% | — | Really-simple-plugins Complianz | 14/2/2022 | 17/6/2026 | The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting |