Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.41% | — | Creator LMSAI | 30/9/2026 | 30/9/2026 | Contributor Path Traversal in Creator LMS <= 1.2.19 versions. | |
| Aplazada | Media (5.4) | 0.25% | — | Creator LMSAI | 30/9/2026 | 30/9/2026 | Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions. | |
| Analizada | Alta (7.8) | 0.12% | — | Synology Active Backup FOR Business Recovery Media Creator | 3/6/2026 | 22/7/2026 | An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors. | |
| Aplazada | Media (5.4) | 0.23% | — | Creatorsofcode SimplephpAI | 27/5/2026 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload. | |
| Aplazada | Alta (8.8) | 0.42% | — | Wpfunnels Creator LMSAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue affects Creator LMS: from n/a through <= 1.1.18. | |
| Analizada | Alta (8.7) | 0.47% | — | Lyricvideocreator Lyric Video Creator | 21/3/2026 | 17/6/2026 | Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality. | |
| Aplazada | Alta (7.1) | 0.14% | — | Markbeljaars Table OF Contents CreatorAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table of Contents Creator allows Reflected XSS.This issue affects Table of Contents Creator: from n/a through 1.6.4.1. | |
| Aplazada | Media (4.3) | 0.26% | — | Pencidesign Penci AI Smartcontent CreatorAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in PenciDesign Penci AI SmartContent Creator penci-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Penci AI SmartContent Creator: from n/a through <= 2.0. | |
| Aplazada | Crítica (9.8) | 0.37% | — | PrestashopAIAdvancedpopupcreatorAI | 13/2/2026 | 17/6/2026 | A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized… | |
| Aplazada | Media (5.1) | 0.28% | — | Easy CD DVD Cover CreatorAI | 27/1/2026 | 17/6/2026 | Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows attackers to crash the application. Attackers can generate a 6000-byte payload and paste it into the serial number field to trigger an application crash. | |
| Aplazada | Alta (8.8) | 0.31% | — | Creator LMSAI | 20/1/2026 | 17/6/2026 | The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the get_items_permissions_check function in all versions up to, and including, 1.1.12. This makes it possible… | |
| Aplazada | Media (4.4) | 0.23% | — | Testimonials CreatorAI | 14/1/2026 | 17/6/2026 | The Testimonials Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in… | |
| Aplazada | Media (5.4) | 0.20% | — | Niklaslindemann Bulk Landing Page Creator FOR Wordpress LpageryAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in niklaslindemann Bulk Landing Page Creator for WordPress LPagery lpagery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Landing Page Creator for WordPress LPagery: from n/a through <= 2.4.9. | |
| Aplazada | Media (5.3) | 0.26% | — | Creatorlms Creator LMSAI | 6/1/2026 | 30/9/2026 | Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through <= 1.1.12. | |
| Aplazada | Media (4.3) | 0.15% | — | Animated Pixel Marquee CreatorAI | 12/12/2025 | 17/6/2026 | The Animated Pixel Marquee Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery via the 'marquee' parameter in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the marquee deletion function. This makes it possible for unauthenticated attackers to delete arbitrary… | |
| Aplazada | Media (6.4) | 0.27% | — | Easy MAP CreatorAI | 12/12/2025 | 17/6/2026 | The Easy Map Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Alta (7.1) | 0.15% | — | Alex Furr PDF Creator LiteAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alex Furr PDF Creator Lite pdf-creator-lite allows Stored XSS.This issue affects PDF Creator Lite: from n/a through <= 1.2. | |
| Aplazada | Alta (7.5) | 0.33% | — | QuickcreatorAI | 24/10/2025 | 17/6/2026 | The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticated attackers to view the plugin's API key and subsequently use that to perform… | |
| Aplazada | Media (6.4) | 0.19% | — | Spotify Embed CreatorAI | 12/9/2025 | 30/9/2026 | The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.25% | — | Bulk Youtube Post CreatorAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Tahir Ali Jan Bulk YouTube Post Creator bulk-youtube-post-creator allows Reflected XSS.This issue affects Bulk YouTube Post Creator: from n/a through <= 1.0. | |
| Analizada | Media (6.5) | 0.52% | — | High-logic Fontcreator | 2/6/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trigger this vulnerability which can lead to disclosure of sensitive information. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. | |
| Aplazada | Media (4.3) | 0.14% | — | Ashok G Easy Child Theme CreatorAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator easy-child-theme-creator allows Cross Site Request Forgery.This issue affects Easy Child Theme Creator: from n/a through <= 1.3.1. | |
| Aplazada | Media (6.5) | 0.27% | — | Creatorteam Zoho Creator FormsAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreatorTeam Zoho Creator Forms allows Stored XSS. This issue affects Zoho Creator Forms: from n/a through 1.0.5. | |
| Aplazada | Alta (7.1) | 0.29% | — | Runthings.dev Bulk Page Stub CreatorAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in runthings.dev Bulk Page Stub Creator bulk-page-stub-creator allows Reflected XSS.This issue affects Bulk Page Stub Creator: from n/a through <= 1.1. | |
| Aplazada | Media (5.3) | 0.32% | — | Powercreator CMSAI | 13/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PowerCreator CMS 1.0. Affected is an unknown function of the file /OpenPublicCourse.aspx. The manipulation of the argument cid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… |