Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.64% | — | Enable SVG Webp AND ICO UploadAI | 18/11/2025 | 17/6/2026 | The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.1.3. This is due to insufficient file type validation detecting ICO files, allowing double extension files with the appropriate magic bytes to bypass sanitization while being… | |
| Aplazada | Media (6.4) | 0.22% | — | Enable SVG Webp AND ICO UploadAI | 18/11/2025 | 17/6/2026 | The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Analizada | Media (4.8) | 0.42% | — | WP Enable SVG Project WP Enable SVG | 2/1/2025 | 17/6/2026 | The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts | |
| Modificada | Media (5.4) | 0.32% | — | Ideastocode Enable Svg, Webp & ICO Upload | 17/7/2023 | 17/6/2026 | The Enable SVG, WebP & ICO Upload WordPress plugin through 1.0.3 does not sanitize SVG file contents, leading to a Cross-Site Scripting vulnerability. | |
| Modificada | Media (5.4) | 0.54% | — | Enable SVG Uploads Project Enable SVG Uploads | 10/7/2023 | 17/6/2026 | The Enable SVG Uploads WordPress plugin through 2.1.5 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Modificada | Media (5.4) | 0.56% | — | Ideastocode Enable Svg, Webp & ICO Upload | 1/8/2022 | 17/6/2026 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress. | |
| Modificada | Alta (8.8) | 1.3% | — | Ideastocode Enable Svg, Webp & ICO Upload | 1/8/2022 | 17/6/2026 | Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress. | |
| Modificada | Media (5.4) | 0.60% | — | Room 34 Creative Services Enable SVG | 30/5/2022 | 17/6/2026 | The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads |