Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.15%—If-so Dynamic ContentAI7/10/20267/10/2026
The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
AplazadaBaja (3.1)0.12%—If-so Dynamic ContentAI1/10/20261/10/2026
The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page.
AplazadaMedia (4.7)0.18%—IF SO Dynamic ContentAI1/10/20261/10/2026
The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who opens a crafted link.
AplazadaAlta (7.1)0.18%—If-so Dynamic Content PersonalizationAI30/9/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Reflected XSS.This issue affects If-So Dynamic Content Personalization: from n/a through 1.10.1.
AplazadaCrítica (9.3)0.40%—If-so Dynamic Content PersonalizationAI13/8/202614/8/2026
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
AplazadaMedia (6.5)0.21%—If-so Dynamic Content PersonalizationAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through <= 1.9.4.
AplazadaMedia (6.5)0.19%—If-so Dynamic Content PersonalizationAI17/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through <= 1.9.3.1.
AnalizadaMedia (5.4)0.30%—If-so Dynamic Content Personalization15/5/202517/6/2026
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaMedia (4.3)0.47%—If-so IF SO Dynamic Content PersonalizationAI21/11/202417/6/2026
The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.2.1 via the 'ifso-show-post' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.5)0.44%—If-so Dynamic Content PersonalizationAI11/6/202417/6/2026
Missing Authorization vulnerability in If So Plugin If-So Dynamic Content Personalization.This issue affects If-So Dynamic Content Personalization: from n/a through 1.7.1.
AnalizadaAlta (8.8)0.69%—Oretnom23 Block Inserter FOR Dynamic Content1/3/202417/6/2026
A vulnerability has been found in SourceCodester Block Inserter for Dynamic Content 1.0 and classified as critical. This vulnerability affects unknown code of the file view_post.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaMedia (5.4)0.33%—If-so Dynamic Content Personalization10/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If So Plugin If-So Dynamic Content Personalization allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through 1.6.3.1.
ModificadaAlta (8.8)0.27%—Ovation Dynamic Content FOR Elementor5/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L. Dynamic Content for Elementor.This issue affects Dynamic Content for Elementor: from n/a before 2.12.5.
ModificadaMedia (4.9)1.4%—Dynamic Content Elements Project Dynamic Content Elements28/4/202117/6/2026
The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allows SQL Injection via a backend user account.
ModificadaMedia (5.4)0.66%—Ovation Dynamic Content19/3/202117/6/2026
Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter.
ModificadaMedia (5.3)1.6%—Dynamic Content Elements Project Dynamic Content Elements3/2/202017/6/2026
The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request.
Orbitaley — Vulnerabilidades