Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 319 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaBaja (3.7)0.18%—Smackcoders WP Ultimate CSV ImporterAI3/10/20263/10/2026
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a…
RecibidaBaja (3.5)0.14%—Smackcoders WP Ultimate CSV ImporterAI3/10/20263/10/2026
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite…
AplazadaMedia (5.3)0.20%—Smackcoders WP Ultimate CSV ImporterAI1/10/20261/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1.
AplazadaMedia (4.1)0.31%—Smackcoders WP Ultimate CSV ImporterAI29/8/202631/8/2026
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.
AplazadaCrítica (9.1)0.50%—Really Simple CSV ImporterAI23/7/202623/7/2026
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
AplazadaAlta (8.8)1.1%—Smackcoders WP Ultimate CSV ImporterAI11/7/202613/7/2026
The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and…
AplazadaMedia (4.4)0.24%—WP Ultimate CSV Importer Infinite Scroll Ajax Load MoreAI10/7/202614/7/2026
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AplazadaAlta (8.7)0.61%—Woocommerce CSV ImporterAI17/5/202617/6/2026
Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX action. Attackers can craft POST requests with directory traversal sequences in the filename parameter to delete…
AplazadaMedia (5.9)0.26%—Jason Judge CSV Importer ImprovedAI20/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason Judge CSV Importer Improved csv-importer-improved allows Stored XSS.This issue affects CSV Importer Improved: from n/a through <= 0.6.1.
AplazadaCrítica (10)0.51%—Webtechglobal Easy CSV ImporterAI14/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WebTechGlobal Easy CSV Importer BETA easy-csv-importer allows Upload a Web Shell to a Web Server.This issue affects Easy CSV Importer BETA: from n/a through <= 7.0.0.
ModificadaAlta (8.8)0.26%—Deniskobozev CSV Importer17/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Denis Kobozev CSV Importer.This issue affects CSV Importer: from n/a through 0.3.8.
ModificadaAlta (8.8)1.6%—Smackcoders WP Ultimate CSV Importer4/8/202317/6/2026
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to execute code…
ModificadaAlta (8.8)1.6%—Smackcoders WP Ultimate CSV Importer4/8/202317/6/2026
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to create a PHP…
ModificadaAlta (8.8)0.79%—Smackcoders WP Ultimate CSV Importer4/8/202317/6/2026
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_values' function. This makes it possible for authenticated attackers, with minimal permissions such as an author, if the administrator…
ModificadaAlta (7.5)0.68%—Smackcoders WP Ultimate CSV Importer4/8/202317/6/2026
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction in export folder indexing in versions up to, and including, 7.9.8. This makes it possible for unauthenticated attackers to list and view exported files.
ModificadaMedia (6.1)0.79%—Ultimate Woocommerce CSV Importer Project Ultimate Woocommerce CSV Importer27/6/202217/6/2026
The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (7.5)6.1%—Comdev CSV Importer3/10/200616/6/2026
PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook 3.1, (6) Comdev Links Directory 3.1, (7) Comdev News Publisher…