Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Favicon RotatorAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <= 1.2.11 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Phbernard FaviconAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phbernard Favicon favicon-by-realfavicongenerator allows Reflected XSS.This issue affects Favicon: from n/a through <= 1.3.46. | |
| Aplazada | Baja (2.1) | 0.35% | — | Dh1011 Auto-faviconAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of the component MCP Tool. The manipulation of the argument image_url results in server-side request forgery. The attack may… | |
| Analizada | Media (4.8) | 0.24% | — | Pixelite Responsive Favicons | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XSS).This issue affects Responsive Favicons: from 0.0.0 before 2.0.2. | |
| Aplazada | Media (5.9) | 0.25% | — | Robert Cummings Quick FaviconAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Cummings Quick Favicon quick-favicon allows Stored XSS.This issue affects Quick Favicon: from n/a through <= 0.22.8. | |
| Aplazada | Alta (7.1) | 0.15% | — | Mangup Personal FaviconAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon personal-favicon allows Stored XSS.This issue affects Personal Favicon: from n/a through <= 2.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Origothemes Extra Options FaviconsAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OrigoThemes Extra Options – Favicons extra-options-favicons allows Stored XSS.This issue affects Extra Options – Favicons: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.1) | 0.17% | — | Rockemmusic Favicon MY BlogAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in rockemmusic Favicon My Blog favicon-my-blog allows Stored XSS.This issue affects Favicon My Blog: from n/a through <= 1.0.2. | |
| Analizada | Media (6.5) | 0.25% | — | Pixeljar Favicon Generator | 13/9/2024 | 17/6/2026 | The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server | |
| Analizada | Media (6.8) | 0.29% | — | Pixeljar Favicon Generator | 13/9/2024 | 17/6/2026 | The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server | |
| Modificada | Alta (8.1) | 0.27% | — | Pixeljar Favicon Generator | 24/8/2024 | 17/6/2026 | The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the output_sub_admin_page_0 function. This makes it possible for unauthenticated attackers to delete arbitrary files on the server via a… | |
| Modificada | Media (4.8) | 0.28% | — | Nihal Wpfavicon | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nazmul Hossain Nihal WPFavicon allows Stored XSS.This issue affects WPFavicon: from n/a through 2.1.1. | |
| Aplazada | Media (5.9) | 0.26% | — | Bryan Hadaway Site FaviconAI | 3/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bryan Hadaway Site Favicon allows Stored XSS.This issue affects Site Favicon: from n/a through 0.2. | |
| Aplazada | Crítica (9.1) | 0.81% | — | PK Favicon ManagerAI | 14/5/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Pk Favicon Manager.This issue affects Pk Favicon Manager: from n/a through 2.1. | |
| Aplazada | Alta (7.1) | 0.35% | — | Eftakhairul Islam AND Sirajus Salayhin Easy SET FaviconAI | 29/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eftakhairul Islam & Sirajus Salayhin Easy Set Favicon allows Reflected XSS.This issue affects Easy Set Favicon: from n/a through 1.1. | |
| Aplazada | Media (4.3) | 0.20% | — | Philippe Bernard FaviconAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Philippe Bernard Favicon.This issue affects Favicon: from n/a through 1.3.29. | |
| Aplazada | Alta (7.1) | 0.38% | — | Archetyped Favicon RotatorAI | 28/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Archetyped Favicon Rotator allows Reflected XSS.This issue affects Favicon Rotator: from n/a through 1.2.10. | |
| En análisis | Media (6.5) | 0.78% | — | Grimmdude ALL IN ONE Favicon | 23/2/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arne Franken All In One Favicon.This issue affects All In One Favicon: from n/a through 4.7. | |
| Modificada | Alta (8.8) | 0.23% | — | Matiass Shockingly Simple Favicon | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Matias s Shockingly Simple Favicon plugin <= 1.8.2 versions. | |
| Modificada | Alta (8.8) | 0.49% | — | Favicon BY Realfavicongenerator | 6/6/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function install_new_favicon of the file admin/class-favicon-by-realfavicongenerator-admin.php. The manipulation leads to cross-site request forgery. It is possible to initiate… | |
| Modificada | Media (4.3) | 0.31% | — | Sedlex Favicon-switcher | 21/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SedLex FavIcon Switcher plugin <= 1.2.11 at WordPress allows plugin settings change. | |
| Modificada | Media (6.1) | 0.88% | — | Favicon BY Realfavicongenerator | 11/4/2022 | 17/6/2026 | The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.5) | 0.55% | — | Genie WP Favicon Project Genie WP Favicon | 8/11/2021 | 17/6/2026 | The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack | |
| Modificada | Media (6.1) | 0.83% | — | Favicon BY Realfavicongenerator | 30/8/2021 | 17/6/2026 | The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator. | |
| Modificada | Media (4.8) | 2.0% | — | Techotronic ALL IN ONE Favicon | 16/7/2018 | 17/6/2026 | Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text. |