Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.82% | — | Sigmaplugin Advanced Database CleanerAI | 20/5/2026 | 24/7/2026 | The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 'template' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server,… | |
| Aplazada | Media (6.4) | 0.28% | — | Sigmaplugin Advanced Database Cleaner PROAI | 7/1/2026 | 30/9/2026 | Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10. | |
| Aplazada | Media (4.3) | 0.13% | — | Sigmaplugin Advanced Database CleanerAI | 31/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allows Cross Site Request Forgery.This issue affects Advanced Database Cleaner: from n/a through <= 3.1.6. | |
| Aplazada | Media (4.3) | 0.23% | — | Sigmaplugin Advanced Database CleanerAI | 25/10/2025 | 17/6/2026 | The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to missing or incorrect nonce validation on the aDBc_prepare_elements_to_clean() function. This makes it possible for unauthenticated attackers to alter the keep last… | |
| Modificada | Media (4.9) | 0.56% | — | Meowapps Database Cleaner | 10/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jordy Meow Database Cleaner allows Relative Path Traversal.This issue affects Database Cleaner: from n/a through 1.0.5. | |
| Modificada | Alta (7.2) | 1.1% | — | Sigmaplugin Advanced Database Cleaner | 5/2/2024 | 17/6/2026 | The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This makes it possible for authenticated attacker, with administrator access and above, to inject a PHP… | |
| Modificada | Alta (7.5) | 0.48% | — | Meowapps Database Cleaner | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Database Cleaner: Clean, Optimize & Repair.This issue affects Database Cleaner: Clean, Optimize & Repair: from n/a through 0.9.8. | |
| Modificada | Alta (7.2) | 0.74% | — | Sigmaplugin Advanced Database Cleaner | 19/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Younes JFR. Advanced Database Cleaner.This issue affects Advanced Database Cleaner: from n/a through 3.1.2. | |
| Modificada | Alta (8.8) | 0.26% | — | Sigmaplugin Advanced Database Cleaner | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner plugin <= 3.1.1 versions. | |
| Modificada | Media (6.1) | 0.79% | — | Sigmaplugin Advanced Database Cleaner | 17/7/2022 | 17/6/2026 | The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.80% | — | Sigmaplugin Advanced Database Cleaner | 21/2/2022 | 17/6/2026 | The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Alta (7.2) | 1.2% | — | Sigmaplugin Advanced Database Cleaner | 18/3/2021 | 17/6/2026 | Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks. |