Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.26% | — | Fatcatapps Easy Pricing TablesAI | 30/9/2026 | 30/9/2026 | Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. | |
| Analizada | Media (5.4) | 0.33% | — | Fatcatapps Easy Pricing Tables | 6/11/2024 | 17/6/2026 | The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fontFamily’ attribute in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.36% | — | Fatcatapps Easy Pricing TablesAI | 30/10/2024 | 17/6/2026 | The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.2.5. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Media (6.1) | 1.5% | — | Fatcatapps Easy Pricing Tables | 27/6/2022 | 17/6/2026 | The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.56% | — | Fatcatapps Easy Pricing Tables | 2/6/2022 | 17/6/2026 | Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables plugin <= 3.1.2 at WordPress. | |
| Modificada | Media (6.5) | 0.53% | — | Fatcatapps Easy Pricing Tables | 7/3/2022 | 17/6/2026 | The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, which will be put in the trash |