Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

262 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.19%—Real Estate ManagerAI30/9/202630/9/2026
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
En análisisMedia (5.3)0.26%—Ordasoft Real Estate ManagerAI28/9/202630/9/2026
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same…
En análisisCrítica (9.3)0.28%—Ordasoft Real Estate ManagerAI28/9/202630/9/2026
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field…
AplazadaAlta (7.1)0.25%—Estatik Real Estate PluginAI19/9/202621/9/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.
AplazadaAlta (7.1)0.28%—Realtyna Organic IDXAIRealtyna WPL Real EstateAI17/9/202618/9/2026
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link…
AplazadaMedia (4.3)0.10%—Real Estate PapiAI6/9/20268/9/2026
The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate ,…
AplazadaMedia (5.5)0.43%—Itsourcecode Real Estate Management SystemAI24/8/202627/8/2026
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The…
AplazadaAlta (7.1)0.25%—Simplyrets Real Estate IDXAI19/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.
AplazadaAlta (8.8)0.52%—Essential Real EstateAI18/8/202620/8/2026
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
AplazadaAlta (7.5)0.36%—Real Estate Manager PROAI15/8/202620/8/2026
The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target user ID as a media attachment ID during user capability checks. This…
AplazadaBaja (3.7)0.14%—Estatik Real Estate PluginAI12/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is…
AplazadaAlta (7.5)0.23%—Estatik Real Estate PluginAI7/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the…
AplazadaMedia (5.3)0.30%—Estatik Real Estate PluginAI6/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a…
AplazadaMedia (4.3)0.16%—Mlsimport IDX Plugin MLS Plugin FOR Real Estate ListingsAI5/8/202626/8/2026
The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress…
AplazadaMedia (6.4)0.33%—Realestateconnected Easy Property ListingsAI1/8/202612/8/2026
The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to, and including, 3.5.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaCrítica (9.8)4.0%—Realtyna Organic IDXAIRealtyna WPL Real EstateAI31/7/202612/8/2026
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by…
AplazadaCrítica (9.8)0.83%—Realtyna Organic IDXAIRealtyna WPL Real EstateAI27/7/202627/7/2026
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it…
AplazadaAlta (7.1)0.25%—Real Estate Manager PROAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
AplazadaAlta (7.1)0.25%—Webcodingplace Real Estate Manager PROAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Real Estate Manager Pro real-estate-manager-pro allows Reflected XSS.This issue affects Real Estate Manager Pro: from n/a through <= 12.8.3.
AplazadaAlta (7.1)0.54%—MicrorealestateAI7/7/20267/7/2026
Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3.
AplazadaMedia (5.3)0.36%—MicrorealestateAI7/7/20267/7/2026
Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.
AplazadaAlta (7.1)0.36%—MicrorealestateAI7/7/20267/7/2026
Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.
AplazadaAlta (7.1)0.36%—Microrealestate Micro Real EstateAI7/7/20267/7/2026
MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0-alpha3.
AplazadaAlta (8.8)0.60%—MicrorealestateAI7/7/20267/7/2026
MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through 1.0.0-alpha3.
AplazadaAlta (7.1)0.25%—Real EstateAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.