Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | — | Calmar-webmedia Total DonationsAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Calmar-webmedia Total DonationsAI | 19/8/2026 | 20/8/2026 | Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Accept Donations With Paypal AND StripeAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. | |
| Aplazada | Crítica (9.3) | 0.42% | — | Loopus WP Attractive Donations SystemAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Blind SQL Injection.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from… | |
| Aplazada | Alta (7.5) | 0.43% | — | Loopus WP Attractive Donations SystemAI | 8/1/2026 | 30/9/2026 | Missing Authorization vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from n/a through <= 1.25. | |
| Aplazada | Media (4.7) | 0.49% | — | Scott Paterson Accept Donations With Paypal AND StripeAI | 24/12/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.5.2. | |
| Aplazada | Media (4.3) | 0.13% | — | Loopus WP Attractive Donations SystemAI | 16/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Cross Site Request Forgery.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from n/a through <= 1.25. | |
| Analizada | Media (4.1) | 0.25% | — | Kieranoshea Donations | 2/12/2025 | 17/6/2026 | The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users, such as admin to perform SQL injection attacks | |
| Aplazada | Alta (7.1) | 0.13% | — | Loopus WP Attractive Donations SystemAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System wp-attractive-donations-system-easy-stripe-paypal-donations allows Stored XSS.This issue affects WP Attractive Donations System: from n/a through < 1.29. | |
| Aplazada | Media (5.9) | 0.18% | — | Wp-ecommerce Recurring Paypal DonationsAI | 22/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations recurring-donation allows Stored XSS.This issue affects Recurring PayPal Donations: from n/a through <= 1.8. | |
| Aplazada | Alta (7.1) | 0.22% | — | Calmar-webmedia Total DonationsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in binti76 Total Donations total-donations allows Reflected XSS.This issue affects Total Donations: from n/a through <= 3.0.8. | |
| Modificada | Media (6.1) | 0.15% | — | Wpplugin Accept Donations With Paypal | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Stored XSS.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.4.5. | |
| Aplazada | Media (6.1) | 0.32% | — | Accept Donations With Paypal StripeAI | 23/2/2025 | 17/6/2026 | The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (6.1) | 0.18% | — | Harryhe Gtpayment Donations | 21/12/2024 | 17/6/2026 | The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Modificada | Alta (8.8) | 0.60% | — | Rednao Donations Made Easy - Smart Donations | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in RedNao Donations Made Easy – Smart Donations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12. | |
| Analizada | Media (6.1) | 0.35% | — | Iseard Kudos Donations | 28/11/2024 | 17/6/2026 | The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Media (6.1) | 0.41% | — | Iseard Kudos Donations | 28/11/2024 | 17/6/2026 | The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Media (5.4) | 0.25% | — | Wp-ecommerce Recurring Paypal Donations | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations allows Stored XSS.This issue affects Recurring PayPal Donations: from n/a through 1.7. | |
| Modificada | Alta (8.8) | 0.29% | — | Rednao Donations Made Easy - Smart Donations | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12. | |
| Modificada | Media (6.1) | 0.22% | — | Rednao Donations Made Easy - Smart Donations | 14/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations allows Stored XSS.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12. | |
| Modificada | Crítica (9.8) | 0.68% | — | Rednao Donations Made Easy - Smart Donations | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedNao Donations Made Easy – Smart Donations allows SQL Injection.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12. | |
| Modificada | Media (6.1) | 0.41% | — | Rednao Smart Donations | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao Donations Made Easy – Smart Donations plugin <= 4.0.12 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Rednao Smart Donations | 25/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao Donations Made Easy – Smart Donations plugin <= 4.0.12 versions. | |
| Modificada | Alta (8.8) | 0.34% | — | Wpzone Potent Donations FOR Woocommerce | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Potent Donations for WooCommerce plugin <= 1.1.9 versions. | |
| Modificada | Media (4.8) | 0.56% | — | Tipsandtricks-hq Donations VIA Paypal | 28/11/2022 | 17/6/2026 | The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |