Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.61% | — | Catchthemes Catch Dark ModeAI | 17/9/2025 | 25/9/2026 | The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0 via the 'catch_dark_mode' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing… | |
| Modificada | Alta (8.8) | 0.37% | — | Quomodosoft QS Dark Mode | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in quomodosoft QS Dark Mode qs-dark-mode allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects QS Dark Mode: from n/a through <= 3.0. | |
| Modificada | Alta (8.8) | 0.95% | — | Catchthemes Catch Dark Mode | 4/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Catch Themes Catch Dark Mode catch-dark-mode allows PHP Local File Inclusion.This issue affects Catch Dark Mode: from n/a through <= 2.0.1. | |
| Aplazada | Media (6.4) | 0.33% | — | QS Dark Mode PluginAI | 1/10/2024 | 17/6/2026 | The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Analizada | Alta (8.8) | 0.21% | — | Naiches Dark Mode FOR WP Dashboard | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3. | |
| Modificada | Media (4.3) | 0.34% | — | Wppool WP Dark Mode | 6/6/2024 | 17/6/2026 | The WP Dark Mode – WordPress Dark Mode Plugin for Improved Accessibility, Dark Theme, Night Mode, and Social Sharing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdm_social_share_save_options function in all versions up to, and including, 5.0.4. This… | |
| Aplazada | Media (6.5) | 0.33% | — | Softlab Dracula Dark ModeAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Dracula Dark Mode - The Revolutionary Dark Mode Plugin For WordPress allows Stored XSS.This issue affects Dracula Dark Mode - The Revolutionary Dark Mode Plugin For WordPress: from n/a through 1.0.8. | |
| Modificada | Alta (8.8) | 0.29% | — | Droitthemes Droit Dark Mode | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DroitThemes Droit Dark Mode.This issue affects Droit Dark Mode: from n/a through 1.1.2. | |
| Modificada | Media (4.3) | 0.68% | — | Wppool WP Dark Mode | 27/3/2023 | 17/6/2026 | The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using it to load a PHP template. This leads to Local File Inclusion on servers where non-existent directories may be traversed, or when chained with another vulnerability allowing arbitrary directory… | |
| Modificada | Media (5.4) | 0.46% | — | Wppool WP Dark Mode | 21/2/2023 | 17/6/2026 | The WP Dark Mode WordPress plugin before 4.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack | |
| Modificada | Media (4.8) | 0.64% | — | Dark Mode Project Dark Mode | 13/1/2018 | 17/6/2026 | An issue was discovered in the dark-mode plugin 1.6 for WordPress. XSS exists via the wp-admin/profile.php dark_mode_end parameter. | |
| Modificada | Media (4.8) | 0.64% | — | Dark Mode Project Dark Mode | 13/1/2018 | 17/6/2026 | An issue was discovered in the dark-mode plugin 1.6 for WordPress. XSS exists via the wp-admin/profile.php dark_mode_start parameter. |