Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | WP Cookie NoticeAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions. | |
| Aplazada | Crítica (10) | 0.52% | — | WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 31/8/2026 | 1/9/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1. | |
| Aplazada | Media (6.5) | 0.22% | — | WP Cookie NoticeAI | 18/8/2026 | 20/8/2026 | Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions. | |
| Aplazada | Media (5.3) | 0.28% | — | Silkentrepreneur WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3. | |
| Aplazada | Media (5.3) | 0.25% | — | Webtoffee WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.7. | |
| Aplazada | Media (5.9) | 0.21% | — | Humanityco Cookie NoticeAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Humanityco Cookie Notice & Compliance for GDPR / CCPA cookie-notice allows Stored XSS.This issue affects Cookie Notice & Compliance for GDPR / CCPA: from n/a through <= 2.5.8. | |
| Aplazada | Media (6.4) | 0.22% | — | HU Webuni Cookie Notice Compliance FOR Gdpr CcpaAI | 22/11/2025 | 17/6/2026 | The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookies_accepted shortcode in all versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.29% | — | Webtoffee WP Cookie Notice FOR Gdpr Ccpa Eprivacy ConsentAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3. | |
| Aplazada | Alta (7.1) | 0.22% | — | Christophrado Cookie-notice-consentAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in christophrado Cookie Notice & Consent cookie-notice-consent allows Stored XSS.This issue affects Cookie Notice & Consent: from n/a through <= 1.6.4. | |
| Aplazada | Alta (7.2) | 0.30% | — | Cookie Notice ConsentAI | 9/10/2025 | 17/6/2026 | The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uuid parameter in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.5) | 0.21% | — | Gdprinfo Cookie Notice AND Consent BannerAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice & Consent Banner for GDPR & CCPA Compliance cookie-notice-and-consent-banner allows Stored XSS.This issue affects Cookie Notice & Consent Banner for GDPR & CCPA Compliance: from n/a through <=… | |
| Aplazada | Media (4.3) | 0.16% | — | Webtoffee WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Cross Site Request Forgery.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 3.8.0. | |
| Aplazada | Media (5.3) | 0.45% | — | Themeqx Gdpr-cookie-noticeAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in themeqx GDPR Cookie Notice gdpr-cookie-notice allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GDPR Cookie Notice: from n/a through <= 1.2.0. | |
| Analizada | Media (4.8) | 0.31% | — | Dcurasi Cookie Notice BAR | 20/2/2025 | 17/6/2026 | The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages… | |
| Aplazada | Media (4.4) | 0.37% | — | HU Tech Cookie NoticeAI | 16/8/2024 | 17/6/2026 | The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cookie_notice_options[refuse_code_head]' parameter in versions up to, and including, 2.4.17.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (4.8) | 0.37% | — | Christophrado Cookie Notice & Consent | 25/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christoph Rado Cookie Notice & Consent plugin <= 1.6.0 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Hu-manity Cookie Notice & Compliance FOR Gdpr / Ccpa | 7/5/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Hu-manity.Co Cookie Notice & Compliance for GDPR / CCPA plugin <= 2.4.6 versions. | |
| Modificada | Media (5.4) | 0.46% | — | Hu-manity Cookie Notice & Compliance FOR Gdpr / Ccpa | 27/3/2023 | 17/6/2026 | The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.4.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.8) | 0.62% | — | Hu-manity Cookie Notice & Compliance FOR Gdpr / Ccpa | 27/9/2021 | 17/6/2026 | The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Text setting when outputting it in an attribute in the frontend, allowing high privilege users such as admin to perform Cross-Site Scripting even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 0.62% | — | Gdprinfo Cookie Notice & Consent Banner FOR Gdpr & Ccpa Compliance | 6/9/2021 | 17/6/2026 | The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customization options. |