Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 296 respecto a la semana anterior
Críticas / altas1350▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 1.1% | — | CBX Bookmark FavoriteAI | 6/1/2026 | 17/6/2026 | The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.18% | — | Sabuj Kundu CBX Bookmark AND FavoriteAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Sabuj Kundu CBX Bookmark & Favorite cbxwpbookmark allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CBX Bookmark & Favorite: from n/a through <= 2.0.1. | |
| Aplazada | Alta (7.5) | 0.43% | — | Kylephillips FavoritesAI | 6/11/2025 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kyle Phillips Favorites favorites allows PHP Local File Inclusion.This issue affects Favorites: from n/a through <= 2.3.6. | |
| Aplazada | Baja (2.1) | 0.28% | — | Cloudfavorites Favorites-webAI | 4/8/2025 | 17/6/2026 | A vulnerability classified as critical was found in cloudfavorites favorites-web up to 1.3.0. Affected by this vulnerability is the function getCollectLogoUrl of the file app/src/main/java/com/favorites/web/CollectController.java. The manipulation of the argument url leads to server-side request forgery. The attack… | |
| Aplazada | Media (6.1) | 0.33% | — | Custom Admin BAR FavoritesAI | 25/4/2025 | 17/6/2026 | The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Analizada | Baja (3.5) | 0.26% | — | Favoriteposts Favorites | 25/3/2025 | 17/6/2026 | The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (7.1) | 0.23% | — | Thobian Network-favoritesAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thobian Network-Favorites network-favorites allows Reflected XSS.This issue affects Network-Favorites: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.26% | — | Dimitar A MY Favorite CarsAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dimitar A. My Favorite Car my-favorite-cars allows Reflected XSS.This issue affects My Favorite Car: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.76% | — | Favorites WEBAI | 5/12/2024 | 17/6/2026 | Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java. | |
| Aplazada | Media (6.5) | 0.27% | — | Takashimatsuyama MY FavoritesAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama My Favorites my-favorites allows Stored XSS.This issue affects My Favorites: from n/a through <= 1.4.1. | |
| Modificada | Media (5.4) | 0.30% | — | Takashimatsuyama MY Favorites | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama My Favorites my-favorites allows DOM-Based XSS.This issue affects My Favorites: from n/a through <= 1.4.3. | |
| Aplazada | Media (4.3) | 0.25% | — | Huseyin Berberoglu WP Favorite PostsAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Huseyin Berberoglu WP Favorite Posts.This issue affects WP Favorite Posts: from n/a through 1.6.8. | |
| Aplazada | Media (6.5) | 0.32% | — | Codeboxr Team CBX Bookmark AND FavoriteAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeboxr Team CBX Bookmark & Favorite cbxwpbookmark allows Stored XSS.This issue affects CBX Bookmark & Favorite: from n/a through 1.7.20. | |
| Aplazada | Alta (7.6) | 0.52% | — | Codeboxr CBX Bookmark AND FavoriteAI | 15/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codeboxr Team CBX Bookmark & Favorite.This issue affects CBX Bookmark & Favorite: from n/a through 1.7.20. | |
| Aplazada | Media (6.4) | 0.38% | — | FavoritesAI | 30/3/2024 | 17/6/2026 | The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user_favorites' shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping on user supplied attributes such as 'no_favorites'. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.35% | — | Codeboxr CBX Bookmark & Favorite | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeboxr Team CBX Bookmark & Favorite allows Stored XSS.This issue affects CBX Bookmark & Favorite: from n/a through 1.7.13. | |
| Modificada | Media (5.4) | 0.50% | — | Favorites-web Project Favorites-web | 12/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in cloudfavorites favorites-web 1.3.0. Affected by this issue is some unknown functionality of the component Nickname Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Media (4.3) | 0.32% | — | Jenkins Favorite View | 16/8/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Favorite View Plugin 5.v77a_37f62782d and earlier allows attackers to add or remove views from another user's favorite views tab bar. | |
| Modificada | Media (5.4) | 0.69% | — | Favoriteposts Favorites | 31/5/2023 | 17/6/2026 | The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_favorites' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Media (5.4) | 0.52% | — | Favorites-web Project Favorites-web | 13/1/2023 | 17/6/2026 | A vulnerability was found in ityouknow favorites-web. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Comment Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (5.4) | 0.31% | — | Crowdfavorite Progressive License | 1/8/2022 | 17/6/2026 | The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be… | |
| Modificada | Media (5.4) | 0.82% | — | Jenkins Favorite | 15/3/2022 | 17/6/2026 | Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure or Item/Create permissions. | |
| Modificada | Media (5.3) | 19% | — | Nagios Favorites | 3/2/2021 | 17/6/2026 | The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account. | |
| Modificada | Media (6.1) | 25% | — | Nagios Favorites | 3/2/2021 | 17/6/2026 | The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Favorites | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Favorites extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. |