Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.37% | — | CornerstoneAI | 24/6/2026 | 25/6/2026 | The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to every logged-in user on any wp-admin page, allowing any authenticated user to evaluate dynamic content tokens against arbitrary users and disclose… | |
| Aplazada | Alta (7.7) | 0.37% | — | CornerstoneAIOpen Group XAI | 24/6/2026 | 25/6/2026 | The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of any other user, including roles, session token previews and stored billing/shipping fields. This affects the premium co Cornerstone page builder… | |
| Aplazada | Alta (8.5) | 0.36% | — | CornerstoneAI | 17/6/2026 | 17/6/2026 | Subscriber SQL Injection in Cornerstone < 7.8.8 versions. | |
| Aplazada | Alta (8.5) | 0.47% | — | CornerstoneAI | 17/6/2026 | 17/6/2026 | Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions. | |
| Aplazada | Media (6.5) | 0.20% | — | Themeco CornerstoneAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in THEMECO Cornerstone cornerstone allows Stored XSS.This issue affects Cornerstone: from n/a through <= 7.7.3. | |
| Aplazada | Alta (7.1) | 0.33% | — | Archetyped CornerstoneAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Archetyped Cornerstone allows Reflected XSS.This issue affects Cornerstone: from n/a through 0.8.0. | |
| Aplazada | Alta (7.1) | 0.38% | — | Archetyped CornerstoneAI | 28/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Archetyped Cornerstone allows Reflected XSS.This issue affects Cornerstone: from n/a through 0.8.0. | |
| Modificada | Alta (7.5) | 1.4% | — | Cornerstone Project Cornerstone | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Cornerstone, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. |