Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.7) | 0.17% | — | Genetechsolutions PIE RegisterAI | 3/10/2026 | 6/10/2026 | The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code. | |
| Aplazada | Media (5.3) | 0.20% | — | Genetechsolutions PIE RegisterAI | 1/10/2026 | 1/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Shamim Rajani Pie Register pie-register allows Retrieve Embedded Sensitive Data.This issue affects Pie Register: from n/a through 3.8.4.13. | |
| Aplazada | Media (5.4) | 0.23% | — | EC Solutions ECSAI | 15/8/2026 | 26/8/2026 | The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a capability-agnostic nonce that any edit_posts user obtains from the Elementor editor), so a Contributor can write a data-source binding into any post — including… | |
| Aplazada | Media (5.3) | 0.20% | — | Genetechsolutions PIE RegisterAI | 22/6/2026 | 22/6/2026 | The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox. | |
| Aplazada | Media (6.5) | 0.36% | — | Genetechsolutions PIE RegisterAI | 4/4/2026 | 24/7/2026 | The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to change… | |
| Aplazada | Media (5.3) | 0.25% | — | Genetechsolutions PIE RegisterAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Genetech Products Pie Register pie-register allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pie Register: from n/a through <= 3.8.4.8. | |
| Aplazada | Crítica (10) | 16% | — | Genetechsolutions PIE RegisterAI | 9/7/2025 | 17/6/2026 | An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker can… | |
| Modificada | Alta (7.5) | 0.51% | — | Genetechsolutions PIE Register | 21/2/2025 | 17/6/2026 | The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.4 through publicly exposed log files. This makes it possible for… | |
| Modificada | Crítica (9.8) | 0.61% | — | Genetechsolutions PIE Register | 17/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1. | |
| Modificada | Alta (7.8) | 0.28% | — | Cppchecksolutions Cppcheck | 11/9/2023 | 17/6/2026 | An issue in Cppcheck 2.12 dev allows a local attacker to execute arbitrary code via the removeContradiction parameter in token.cpp:1934. | |
| Modificada | Media (5.4) | 24% | — | Genetechsolutions PIE Register | 27/2/2023 | 17/6/2026 | The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability | |
| Modificada | Media (6.5) | 0.34% | — | Genetechsolutions PIE Register | 19/12/2022 | 17/6/2026 | The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts) | |
| Modificada | Media (5.9) | 1.3% | — | Ecisolutions Printanista Managed Print Service | 15/9/2022 | 17/6/2026 | The login form /Login in ECi Printanista Hub (formerly FMAudit Printscout) before 5.5.2 (July 2023) performs expensive RSA key-generation operations, which allows attackers to cause a denial of service (DoS) by requesting that form repeatedly. | |
| Modificada | Crítica (9.8) | 6.4% | — | Genetechsolutions PIE Register | 8/11/2021 | 17/6/2026 | The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection. | |
| Modificada | Alta (8.1) | 9.8% | — | Genetechsolutions PIE Register | 8/11/2021 | 17/6/2026 | The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username | |
| Modificada | Media (6.1) | 1.6% | — | Genetechsolutions PIE Register | 22/4/2021 | 17/6/2026 | The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue. | |
| Modificada | Crítica (9.8) | 1.9% | — | Genetechsolutions PIE Register | 27/8/2019 | 17/6/2026 | The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969. | |
| Modificada | Media (6.1) | 1.5% | — | Genetechsolutions PIE Register | 23/7/2019 | 17/6/2026 | Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session cookies. The component is: File: Login. Parameters: interim-login, wp-lang, and supplied URL. The attack vector is: If a victim clicks a malicious link, the attacker can steal his/her account. The fixed… | |
| Modificada | Crítica (9.8) | 5.3% | — | Genetechsolutions PIE Register | 17/6/2018 | 17/6/2026 | SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid. | |
| Modificada | Media (6.5) | 1.4% | — | Genetechsolutions PIE Register | 16/10/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php. | |
| Modificada | Media (4.3) | 4.4% | — | Genetechsolutions PIE Register | 16/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI. | |
| Modificada | Media (5) | 7.4% | — | Genetechsolutions PIE Register | 23/1/2015 | 17/6/2026 | The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action. | |
| Modificada | Baja (2.6) | 6.1% | — | Genetechsolutions Pie-register | 29/7/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in a… | |
| Modificada | Alta (7.5) | 0.99% | — | Mntechsolutions Theeta CMS | 21/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL commands via the start parameter to (1) forum.php and (2) thread.php in community/, and (3) blog/index.php. | |
| Modificada | Media (4.3) | 1.5% | — | Mntechsolutions Theeta CMS | 21/4/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) forum, and (3) cat parameters to community/thread.php; (4) start and (5) cat parameters to community/forum.php; and (6) start parameter to… |